fix(redact): bearer residue sweep needs a 20-char token floor

redact_for_egress's bearer sweep matched any run of token characters after
the word "Bearer", so ordinary prose ("I'm the bearer of bad news") came
back as "Bearer [redacted] bad news" on every chat and A2A reply. The
gateway and A2A sweeps this PR replaced always required 20+ chars; only
monitoring was floor-less. Restore the floor on the opaque branch and keep
the bracket branch that folds an already-masked residue to one marker.
This commit is contained in:
teknium1
2026-09-12 23:42:44 -07:00
committed by Teknium
parent dd1baee0e4
commit f680431f2e
3 changed files with 15 additions and 6 deletions
@@ -32,11 +32,11 @@ def test_otlp_attrs_redact_strings_and_never_export_profile():
"event": "gateway_health",
"name": "gateway.lifecycle",
"profile": "user@example.com",
"exit_reason": "Bearer top-secret-token for user@example.com",
"exit_reason": "Bearer top-secret-token-0123456789 for user@example.com",
})
assert "hermes.profile" not in attrs
assert "top-secret-token" not in str(attrs)
assert "top-secret-token-0123456789" not in str(attrs)
assert "user@example.com" not in str(attrs)
@@ -48,7 +48,7 @@ def test_resource_attributes_are_allowlisted_and_sanitized():
"service.instance.id": "install-1",
"deployment.environment.name": "staging",
"user.email": "user@example.com",
"authorization": "Bearer top-secret-token",
"authorization": "Bearer top-secret-token-0123456789",
"custom.request.id": "unbounded",
})
@@ -73,13 +73,13 @@ def test_diagnostic_log_attributes_are_allowlisted_redacted_and_profile_free():
"name": "platform.fatal",
"subsystem": "platform.slack",
"profile": "user@example.com",
"error_code": "Bearer top-secret-token",
"error_code": "Bearer top-secret-token-0123456789",
"custom": "must-not-egress",
})
assert "hermes.profile" not in attrs
assert "hermes.custom" not in attrs
assert "top-secret-token" not in str(attrs)
assert "top-secret-token-0123456789" not in str(attrs)