fix(browser): harden browser tool safety boundaries
Add policy gates and output redaction for browser/CDP surfaces, strengthen session ownership tracking, and block credential-like query parameters before third-party browser/web backends receive URLs. Inspired by the agbrowse review: keep local browser magic-link flows possible while preventing cloud reader/browser escalation from receiving opaque token, code, signature, or key query parameters.
This commit is contained in:
@@ -53,6 +53,13 @@ def _redact_cdp_error_text(exc: object) -> str:
|
||||
return "<error redacted>"
|
||||
|
||||
|
||||
def _redact_supervisor_text(value: str) -> str:
|
||||
"""Redact page-originated text before exposing supervisor snapshots."""
|
||||
from agent.redact import redact_sensitive_text
|
||||
|
||||
return redact_sensitive_text(value, force=True)
|
||||
|
||||
|
||||
# ── Config defaults ───────────────────────────────────────────────────────────
|
||||
|
||||
DIALOG_POLICY_MUST_RESPOND = "must_respond"
|
||||
@@ -166,8 +173,8 @@ class PendingDialog:
|
||||
return {
|
||||
"id": self.id,
|
||||
"type": self.type,
|
||||
"message": self.message,
|
||||
"default_prompt": self.default_prompt,
|
||||
"message": _redact_supervisor_text(self.message),
|
||||
"default_prompt": _redact_supervisor_text(self.default_prompt),
|
||||
"opened_at": self.opened_at,
|
||||
"frame_id": self.frame_id,
|
||||
}
|
||||
@@ -194,7 +201,7 @@ class DialogRecord:
|
||||
return {
|
||||
"id": self.id,
|
||||
"type": self.type,
|
||||
"message": self.message,
|
||||
"message": _redact_supervisor_text(self.message),
|
||||
"opened_at": self.opened_at,
|
||||
"closed_at": self.closed_at,
|
||||
"closed_by": self.closed_by,
|
||||
|
||||
Reference in New Issue
Block a user