fix(redact): skip name fields to preserve sandbox identifiers

ULID-derived sandbox names like fabro-01KQR3V9D4VPFFWMNTVH09J48G tripped
the entropy detector and rendered as REDACTED in CLI run output.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
Bryan Helmkamp 2026-05-03 19:57:55 -04:00
parent 93f255c6c4
commit fe342a4bd7
No known key found for this signature in database

View file

@ -15,10 +15,10 @@ fn should_skip_field(key: &str) -> bool {
return true;
}
// Skip common path and directory fields
// Skip common path and directory fields, plus identifier-like names
matches!(
lower.as_str(),
"filepath" | "file_path" | "cwd" | "root" | "directory" | "dir" | "path"
"filepath" | "file_path" | "cwd" | "root" | "directory" | "dir" | "path" | "name"
)
}
@ -182,11 +182,15 @@ mod tests {
assert!(should_skip_field("path"));
}
#[test]
fn skip_field_name() {
assert!(should_skip_field("name"));
}
#[test]
fn skip_field_false_positives() {
assert!(!should_skip_field("content"));
assert!(!should_skip_field("type"));
assert!(!should_skip_field("name"));
assert!(!should_skip_field("text"));
assert!(!should_skip_field("output"));
assert!(!should_skip_field("video"));
@ -195,6 +199,19 @@ mod tests {
assert!(!should_skip_field("consideration"));
}
#[test]
fn redact_json_value_preserves_name_field() {
let input = serde_json::json!({
"name": "fabro-01KQR3V9D4VPFFWMNTVH09J48G",
"content": format!("token={HIGH_ENTROPY_SECRET}"),
});
let redacted = redact_json_value(input);
assert_eq!(redacted["name"], "fabro-01KQR3V9D4VPFFWMNTVH09J48G");
assert_eq!(redacted["content"], "REDACTED");
}
#[test]
fn skip_object_image_type() {
let obj: serde_json::Map<String, Value> =