[Graphite MQ] Draft PR GROUP:spec_3f3909 (PRs 42) - #49
Closed
graphite-app[bot] wants to merge 1 commit into
Closed
graphite-app[bot] wants to merge 1 commit into
graphite-app[bot] wants to merge 1 commit into
Conversation
## Summary
`--dry-run` and `--debug` print request and response bodies to stderr. They hid only a fixed list of lowercase names: `password`, `secret`, `token`, `api_key` and a few more. The Voiceflow API names its fields in camelCase, so most of the secrets it carries printed in full:
- integration credentials: `apiKeySecret`, `keySecret`, `secretKey`, `oauthSecretKey`, `webhookSecret`, `webhookSecretKey`, `authHeaderValue`
- a secret's value in `secret create` and `secret set-value`
- `Authorization` values in API tool and MCP server headers. In responses this applies to API tool headers, which the API returns as saved; MCP header values come back already masked.
Coding agents keep stderr in their transcripts, so a dry run or a debug run leaked these.
The rule now comes from a survey of all 868 property names in the OpenAPI spec (`internal/client/redact.go`):
- **Names** are compared without case or separators. Those ending in `secret`, `secretkey`, `password`, `token`, `apikey` or `privatekey` are hidden, which covers every name the old list had. Counts such as `maxTokens` and identifiers such as `accountSid`, `apiKeySid`, `keyId` and `accessTokenID` stay visible.
- **`credentials`** is hidden whole.
- **A `{key, value}` pair** whose key names a credential, such as an `Authorization` header, hides its value.
- **The secret endpoints** have `defaultValue` and `value` hidden. Elsewhere they stay visible, so a variable's default still shows.
- **Booleans, numbers and null** are never hidden, so `hasPassword: true` still shows.
## Before and after
| | master | this PR |
|---|---|---|
| Secret names the rule hides, out of the spec's 868 | 4 | 11, plus `hasPassword`, which stays visible as a boolean |
| `test/redaction.test.ts` (4 `--dry-run` and 2 `--debug` leak routes) | 6 leak | 6 hidden, ordinary fields kept |
## Test plan
- [x] `gofmt`, `go vet ./...` and `go test ./...` pass; `go.mod` is unchanged.
- [x] `internal/client/redact_test.go` covers:
- the surveyed secret names and the identifiers next to them;
- every name the old list hid;
- credential containers, header pairs and the secret endpoints.
Removing any of the three parts of the rule fails at least one test.
- [x] `test/redaction.test.ts`: each case sends a canary in a secret field, through `--dry-run` or through `--debug` against a local server, and checks the canary never reaches stderr while ordinary fields do. All 6 leak on master.
- [x] Full suite with #37 applied: 84/84. With #37, #38 and the other three fixes from this batch: 101/101.
- [ ] CI: `CLI behaviour` shows master's 4 existing failures until #37 merges.
#39 also edits `internal/client/diagnostics.go`, and the two apply cleanly together.
Not covered: if the API ever sent a malformed response, the SDK's own parse error could quote a raw field value. Only the API could cause that, so it is left as is.
graphite-app
Bot
deleted the
gtmq_spec_3f3909_1790966526806-f963e3ab-bd9c-4f4c-b3fd-38d05c6bccd3
branch
October 2, 2026 18:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This draft PR was created by the Graphite merge queue.
Trunk will be fast forwarded to the HEAD of this PR when CI passes, and the original PRs will be closed.
The following PRs are included in this draft PR: