cde0ad0edd
Consolidated re-apply of #96988 onto current main. Ported from Merit-Systems/OpenInstinct (MIT) opaque-handle autofill design: the model sees vault handles + login metadata, the password is resolved and filled server-side over the supervised CDP socket, and filled values are scrubbed from every browser tool result by an unconditional redaction registry. Rebase adaptations to the Sep-2026 facade/sibling layout: - toolsets: one _HERMES_CORE_TOOLS entry (the browser toolset derives from it) - hermes_cli/main.py: vault parser registered via the subcommand owner table - file_safety: vault/ joins the _READ_DENIED_DIRS credential-dir table - redact: registry scrub runs before the redact_secrets early-return - browser_vault_tool: _run_browser_command now lives in browser_tool_session
22 lines
814 B
Python
22 lines
814 B
Python
"""``hermes vault`` subcommand parser."""
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
def build_vault_parser(subparsers) -> None:
|
|
"""Attach the local encrypted autofill vault subcommand."""
|
|
vault_parser = subparsers.add_parser(
|
|
"vault",
|
|
help="Manage the local encrypted autofill vault (add/list/rm credentials)",
|
|
description=(
|
|
"Store login credentials in a locally encrypted vault. The agent "
|
|
"sees handles and login identifiers (metadata); passwords are "
|
|
"injected server-side by browser_vault_fill on the exact origin "
|
|
"they were saved for and never enter the conversation."
|
|
),
|
|
)
|
|
from hermes_cli.vault import register_cli, vault_command
|
|
|
|
register_cli(vault_parser)
|
|
vault_parser.set_defaults(func=vault_command)
|