fix(redact): repr pass leaves already-masked values alone

The Python-repr pass ran after the MCP probe header scrub and collapsed
'Authorization': 'Digest ***' to '***', erasing the scheme word that scrub
deliberately keeps (tests/hermes_cli/test_mcp_probe_redaction.py went red
on rebase). Skip values that already carry a mask marker.
This commit is contained in:
teknium1
2026-09-13 20:13:37 -07:00
committed by Teknium
parent 19bc8cf3a5
commit 5280dec0ee
2 changed files with 11 additions and 0 deletions
+5
View File
@@ -618,6 +618,11 @@ def _redact_python_repr_fields(text: str) -> str:
# programmatic env lookups just like the ENV/JSON/YAML passes do.
if _ENV_LOOKUP_VALUE_RE.match(value):
return match.group(0)
# An upstream pass (MCP probe header scrub, _mask_token) already masked this
# value; re-masking would erase the scheme word it deliberately kept
# (``'Authorization': 'Digest ***'`` → ``'***'``).
if "***" in value or value.startswith("«redacted:"):
return match.group(0)
# Do not retain head/tail characters here: escaped repr atoms can cross
# a slicing boundary and leave an unescaped quote behind. A full mask is
# parseable for both str and bytes values and leaks no opaque bytes.
+6
View File
@@ -378,6 +378,12 @@ class TestPythonReprFields:
text = "{'model': 'gpt-5', 'token_count': '123'}"
assert redact_sensitive_text(text, force=True) == text
def test_already_masked_repr_value_keeps_its_scheme_word(self):
# An upstream scrub (MCP probe headers) leaves ``Digest ***``; the repr
# pass must not collapse that to a bare ``***`` and lose the scheme.
text = "headers={'Authorization': 'Digest ***'}"
assert redact_sensitive_text(text, force=True) == text
def test_code_file_preserves_secret_shaped_fixture(self):
text = "CONFIG = {'BRAVE_API_KEY': 'fixture-value-1234567890'}"
assert redact_sensitive_text(text, force=True, code_file=True) == text