fix(redact): config.yaml backup copies under HERMES_HOME are secret-bearing too
search_files over $HERMES_HOME returned the token from backups/config/config.yaml.good.<stamp> in cleartext while config.yaml itself was masked; the predicate only matched the exact basename. Same predicate serves the terminal side, so `cat backups/config/config.yaml.good.*` is covered too.
This commit is contained in:
+3
-1
@@ -1028,7 +1028,9 @@ def _is_secret_file_arg(arg: str) -> bool:
|
||||
return False
|
||||
if parts[-1] in _ENV_FILE_BASENAMES or parts[-1] in _SHELL_RC_BASENAMES:
|
||||
return True
|
||||
if parts[-1] != "config.yaml":
|
||||
# ``config.yaml`` plus the ``config.yaml.good.<stamp>`` / ``.corrupt.<stamp>`` copies Hermes
|
||||
# writes under ``backups/config/`` — same contents, same secrets.
|
||||
if parts[-1] != "config.yaml" and not parts[-1].startswith("config.yaml."):
|
||||
return False
|
||||
return hermes_home or ".hermes" in parts[:-1] or _is_under_hermes_home(path)
|
||||
|
||||
|
||||
@@ -1291,6 +1291,7 @@ class TestHermesHomePathClassification:
|
||||
monkeypatch.setattr(file_safety, "_hermes_root_path", lambda: home)
|
||||
assert _is_secret_file_arg(str(home / "config.yaml"))
|
||||
assert _is_secret_file_arg(str(home / "profiles" / "coder" / "config.yaml"))
|
||||
assert _is_secret_file_arg(str(home / "backups" / "config" / "config.yaml.good.20260914-184559"))
|
||||
assert not _is_secret_file_arg(str(tmp_path / "proj" / "config.yaml"))
|
||||
assert not _is_secret_file_arg("config.yaml") # relative, not resolvable to the home
|
||||
|
||||
|
||||
Reference in New Issue
Block a user