forked from farhoodlabs/paperclip
d734bd43d1
## Thinking Path > - Paperclip is the control plane for autonomous AI companies, so agent work needs visible ownership, recovery, and operator controls. > - This local branch had accumulated several related control-plane reliability and operator-experience fixes across recovery actions, watchdog folding, model-profile defaults, mentions, markdown editing, plugin launchers, and small UI polish. > - The branch needed to be converted into a PR against the current `origin/master` without losing dirty work or including lockfile/workflow churn. > - The safest standalone shape is a single rollup PR because the recovery/server/UI files overlap heavily across the local commits and splitting would create avoidable conflicts. > - This pull request replays the local branch onto latest `origin/master`, preserves the uncommitted work as logical commits, and adds a Zod 4 validator compatibility fix found during verification. > - The benefit is that the May 17 local branch can be reviewed and merged as one coherent, conflict-free branch under the 100-file Greptile limit. ## What Changed - Rebased the local May 17 branch work onto current `origin/master` in a dedicated worktree. - Preserved and committed previously dirty changes for recovery retry handling, plugin/sidebar launcher polish, and `.herenow` ignores. - Added recovery-action behavior for returning source issues to `todo` when retrying source-scoped recovery. - Included the existing local recovery/liveness/watchdog fold, Codex cheap-profile, markdown/mention, duplicate-agent, and UI polish commits from the branch. - Normalized shared validator `z.record(...)` schemas to explicit string-key records for Zod 4 compatibility. - Confirmed the PR has no `pnpm-lock.yaml` or `.github/workflows/*` changes and stays below the 100-file Greptile limit. ## Verification - `pnpm install --frozen-lockfile --ignore-scripts` - `npm run install` in `node_modules/.pnpm/sqlite3@5.1.7/node_modules/sqlite3` to build the local native sqlite3 binding after installing with scripts disabled - `pnpm exec vitest run packages/shared/src/validators/issue.test.ts packages/shared/src/project-mentions.test.ts packages/adapter-utils/src/server-utils.test.ts server/src/__tests__/heartbeat-model-profile.test.ts server/src/__tests__/issue-recovery-actions.test.ts server/src/__tests__/issue-agent-mutation-ownership-routes.test.ts server/src/__tests__/heartbeat-active-run-output-watchdog.test.ts server/src/__tests__/plugin-local-folders.test.ts ui/src/components/IssueRecoveryActionCard.test.tsx ui/src/components/Sidebar.test.tsx ui/src/components/SidebarAccountMenu.test.tsx ui/src/components/IssueProperties.test.tsx ui/src/components/MarkdownEditor.test.tsx ui/src/components/MarkdownBody.test.tsx ui/src/lib/duplicate-agent-payload.test.ts ui/src/pages/Routines.test.tsx` - First pass: 13 files passed with 201 passing tests; 3 server files failed before sqlite3 native binding was built. - After rebuilding sqlite3: `server/src/__tests__/heartbeat-model-profile.test.ts`, `server/src/__tests__/issue-recovery-actions.test.ts`, and `server/src/__tests__/heartbeat-active-run-output-watchdog.test.ts` passed/loaded; embedded Postgres tests were skipped by the local host guard. - `pnpm --filter @paperclipai/shared typecheck` - `pnpm --filter @paperclipai/adapter-utils typecheck` - `pnpm --filter @paperclipai/server typecheck` - `pnpm --filter @paperclipai/ui typecheck` ## Risks - Medium risk: this is a broad rollup PR across recovery semantics, server tests, shared validators, and UI surfaces. - Some embedded Postgres tests skipped locally due the host guard, so CI should provide the stronger database-backed signal. - UI changes were covered by component tests, but no browser screenshot was captured in this PR creation pass. - This branch may overlap with existing recovery/liveness PR work; merge this PR independently or restack/close overlapping branches rather than merging duplicate implementations together. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, GPT-5-based coding agent, tool-enabled local repository and GitHub workflow, medium reasoning effort. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [ ] If this change affects the UI, I have included before/after screenshots - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
135 lines
4.5 KiB
TypeScript
135 lines
4.5 KiB
TypeScript
import { redactCommandText } from "@paperclipai/adapter-utils";
|
|
|
|
const SECRET_FIELD_NAME_PATTERN =
|
|
String.raw`[A-Za-z0-9_-]*(?:api[-_]?key|access[-_]?token|auth(?:_?token)?|token|authorization|bearer|secret|passwd|password|credential|jwt|private[-_]?key|cookie|connectionstring)[A-Za-z0-9_-]*`;
|
|
|
|
const SECRET_PAYLOAD_KEY_RE = new RegExp(SECRET_FIELD_NAME_PATTERN, "i");
|
|
const COMMAND_PAYLOAD_KEY_RE =
|
|
/(^command$|^cmd$|command[-_]?line|resolved[-_]?command|PAPERCLIP_RESOLVED_COMMAND)/i;
|
|
const COMMAND_ARGS_PAYLOAD_KEY_RE = /^(commandArgs|command_?args|argv)$/i;
|
|
const JWT_VALUE_RE = /^[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+(?:\.[A-Za-z0-9_-]+)?$/;
|
|
const CLI_SECRET_FLAG_RE = new RegExp(String.raw`^-{1,2}${SECRET_FIELD_NAME_PATTERN}$`, "i");
|
|
const JSON_SECRET_FIELD_TEXT_RE = new RegExp(
|
|
String.raw`((?:"|')?${SECRET_FIELD_NAME_PATTERN}(?:"|')?\s*:\s*(?:"|'))[^"'` + "`" + String.raw`\r\n]+((?:"|'))`,
|
|
"gi",
|
|
);
|
|
const ESCAPED_JSON_SECRET_FIELD_TEXT_RE = new RegExp(
|
|
String.raw`((?:\\")?${SECRET_FIELD_NAME_PATTERN}(?:\\")?\s*:\s*(?:\\"))[^\\\r\n]+((?:\\"))`,
|
|
"gi",
|
|
);
|
|
const SECRET_TEXT_HINTS = [
|
|
"api",
|
|
"key",
|
|
"token",
|
|
"auth",
|
|
"bearer",
|
|
"secret",
|
|
"pass",
|
|
"credential",
|
|
"jwt",
|
|
"private",
|
|
"cookie",
|
|
"connectionstring",
|
|
"sk-",
|
|
"ghp_",
|
|
"gho_",
|
|
"ghu_",
|
|
"ghs_",
|
|
"ghr_",
|
|
] as const;
|
|
export const REDACTED_EVENT_VALUE = "***REDACTED***";
|
|
|
|
function maybeContainsSecretText(input: string) {
|
|
const lower = input.toLowerCase();
|
|
return SECRET_TEXT_HINTS.some((hint) => lower.includes(hint)) || input.includes(".");
|
|
}
|
|
|
|
function isPlainObject(value: unknown): value is Record<string, unknown> {
|
|
if (typeof value !== "object" || value === null || Array.isArray(value)) return false;
|
|
const proto = Object.getPrototypeOf(value);
|
|
return proto === Object.prototype || proto === null;
|
|
}
|
|
|
|
function sanitizeValue(value: unknown): unknown {
|
|
if (value === null || value === undefined) return value;
|
|
if (Array.isArray(value)) return value.map(sanitizeValue);
|
|
if (isSecretRefBinding(value)) return value;
|
|
if (isPlainBinding(value)) return { type: "plain", value: sanitizeValue(value.value) };
|
|
if (!isPlainObject(value)) return value;
|
|
return sanitizeRecord(value);
|
|
}
|
|
|
|
function isSecretRefBinding(value: unknown): value is { type: "secret_ref"; secretId: string; version?: unknown } {
|
|
if (!isPlainObject(value)) return false;
|
|
return value.type === "secret_ref" && typeof value.secretId === "string";
|
|
}
|
|
|
|
function isPlainBinding(value: unknown): value is { type: "plain"; value: unknown } {
|
|
if (!isPlainObject(value)) return false;
|
|
return value.type === "plain" && "value" in value;
|
|
}
|
|
|
|
function sanitizeCommandArgs(args: unknown[]): unknown[] {
|
|
let redactNext = false;
|
|
return args.map((arg) => {
|
|
if (redactNext) {
|
|
redactNext = false;
|
|
return REDACTED_EVENT_VALUE;
|
|
}
|
|
if (typeof arg !== "string") return sanitizeValue(arg);
|
|
if (CLI_SECRET_FLAG_RE.test(arg.trim())) {
|
|
redactNext = true;
|
|
return arg;
|
|
}
|
|
return redactSensitiveText(arg);
|
|
});
|
|
}
|
|
|
|
export function sanitizeRecord(record: Record<string, unknown>): Record<string, unknown> {
|
|
const redacted: Record<string, unknown> = {};
|
|
for (const [key, value] of Object.entries(record)) {
|
|
if (COMMAND_ARGS_PAYLOAD_KEY_RE.test(key) && Array.isArray(value)) {
|
|
redacted[key] = sanitizeCommandArgs(value);
|
|
continue;
|
|
}
|
|
if (COMMAND_PAYLOAD_KEY_RE.test(key) && typeof value === "string") {
|
|
redacted[key] = redactSensitiveText(value);
|
|
continue;
|
|
}
|
|
if (SECRET_PAYLOAD_KEY_RE.test(key)) {
|
|
if (isSecretRefBinding(value)) {
|
|
redacted[key] = sanitizeValue(value);
|
|
continue;
|
|
}
|
|
if (isPlainBinding(value)) {
|
|
redacted[key] = { type: "plain", value: REDACTED_EVENT_VALUE };
|
|
continue;
|
|
}
|
|
redacted[key] = REDACTED_EVENT_VALUE;
|
|
continue;
|
|
}
|
|
if (typeof value === "string" && JWT_VALUE_RE.test(value)) {
|
|
redacted[key] = REDACTED_EVENT_VALUE;
|
|
continue;
|
|
}
|
|
redacted[key] = sanitizeValue(value);
|
|
}
|
|
return redacted;
|
|
}
|
|
|
|
export function redactEventPayload(payload: Record<string, unknown> | null): Record<string, unknown> | null {
|
|
if (!payload) return null;
|
|
if (!isPlainObject(payload)) return payload;
|
|
return sanitizeRecord(payload);
|
|
}
|
|
|
|
export function redactSensitiveText(input: string): string {
|
|
if (!maybeContainsSecretText(input)) return input;
|
|
return redactCommandText(
|
|
input
|
|
.replace(JSON_SECRET_FIELD_TEXT_RE, `$1${REDACTED_EVENT_VALUE}$2`)
|
|
.replace(ESCAPED_JSON_SECRET_FIELD_TEXT_RE, `$1${REDACTED_EVENT_VALUE}$2`),
|
|
REDACTED_EVENT_VALUE,
|
|
);
|
|
}
|