refactor(redact): consolidate CDP-URL log redaction into one chokepoint

The session-log fix (browser_tool._sanitize_url_for_logs) and the
supervisor attach-timeout fix (CDPSupervisor.start) both composed the
same three redactors (redact_sensitive_text -> _redact_url_query_params
-> _redact_url_userinfo) to mask CDP endpoint credentials. Two copies of
one policy drift: tune one site (e.g. add fragment masking) and the other
silently re-leaks.

Promote that composition to a single public helper redact_cdp_url() in
agent/redact.py -- the one place the CDP-URL redaction policy lives -- and
route both call sites through it (_sanitize_url_for_logs becomes a thin
wrapper; the supervisor imports the helper instead of re-composing the
private redactors). Add direct unit tests for the seam covering query
tokens, multiple credentials, userinfo passwords, plain-URL passthrough,
non-string/exception coercion, and None.

No behavior change at the call sites; both leak paths remain closed.
This commit is contained in:
kshitijk4poor
2026-07-01 13:30:36 +05:30
committed by kshitij
parent 265da9cadb
commit c626dded13
4 changed files with 76 additions and 26 deletions
+2 -6
View File
@@ -342,12 +342,8 @@ class CDPSupervisor:
if not self._ready_event.wait(timeout=timeout):
self.stop()
try:
from agent.redact import (
_redact_url_query_params,
_redact_url_userinfo,
redact_sensitive_text,
)
_safe_url = _redact_url_userinfo(_redact_url_query_params(redact_sensitive_text(self.cdp_url)))
from agent.redact import redact_cdp_url
_safe_url = redact_cdp_url(self.cdp_url)
except Exception:
_safe_url = "<cdp_url redacted>"
raise TimeoutError(