Skip to content

feat(daemon): redact secrets in ACP command approval displays - #2781

Closed
lsm wants to merge 2 commits into
devfrom
space/acp-split-8a1-flat-redaction
Closed

lsm wants to merge 2 commits into
devfrom
space/acp-split-8a1-flat-redaction

Conversation

@lsm

@lsm lsm commented Aug 23, 2026 •

Copy link
Copy Markdown
Owner

Extracted from #2711 (ACP split 8/10). Supersedes #2778, which carried this plus shell-script nesting in one slice — split after round-1 review showed the two halves draw independent findings.

What this adds

  • parseAcpCommandWithSpans (shared acp-command.ts): the existing tokenizer now also records each token's raw span in the original line, so a later slice can rewrite tokens in place while preserving the author's quoting. parseAcpCommand becomes a thin wrapper — no behavior change.
  • redactCommandSecrets (daemon acp-command.ts, flat scope — the top-level command only): redacts secret-shaped argument names (--token, -p, --api-key, …), header values (Authorization: …, curl -H/--header), curl user options (-u, --user, --proxy-user, clustered flags with value-taking-option awareness), URL userinfo (including empty-username forms), env-wrapper assignments, and NAME=value right-hand URL userinfo. Windows executable names (C:\…\curl.exe) normalize before command-specific matching.
  • shellQuote for redisplaying tokens safely.
  • getAcpCommandIdentityDigest now hashes the redacted identity, so rotating a credential value no longer starts a fresh ACP conversation — only a real command change does.
  • 25 tests pinning the flat redactor and redaction-aware digest.

Deliberately not here (next slice)

  • Shell-script nesting: sh -c recursion, command tracking across operators, span-anchored in-place rewrite, recursion cutoff, newline handling. No call sites in the query runner yet (those land with host-callback wiring).

Review context carried from #2778 round 1

This slice absorbs six of the ten findings verbatim: Windows name normalization, env-assignment URL userinfo, curl -d data values, --proxy-user, dash-prefixed -u values, empty-username URLs.

Verification

  • bun test packages/daemon/tests/unit/lib/acp/acp-command.test.ts — 25/25
  • knip, tsc --build --noEmit, oxlint, biome — clean

Open in Devin Review

Add parseAcpCommandWithSpans to the shared ACP command parser so callers
can map parsed tokens back to their raw quoting spans, and a
redactCommandSecrets engine in the daemon that redacts secret-shaped
flags, header values, curl user options, URL userinfo, and env-wrapper
assignments before a command is shown in approval prompts. The
command-identity digest now hashes the redacted identity so rotating a
credential does not start a fresh ACP conversation.

Shell-script nesting (sh -c recursion) follows in the next slice.

Extracted from #2711 (ACP split 8/10).
@lsm

lsm commented Aug 23, 2026

Copy link
Copy Markdown
Owner Author

@codex review

devin-ai-integration[bot]

This comment was marked as resolved.

@lsm

lsm commented Aug 23, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@lsm

lsm commented Aug 23, 2026

Copy link
Copy Markdown
Owner Author

Parking this PR open by decision (see #2782): the first ACP release ships bypass-permissions at parity with the SDK path, and the security-hardening slices (approval gating + command redaction) will be revived together with a unified cross-provider permission UX. Branch stays; review feedback is already addressed in-head; no further merge attempts until then.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Unknown error
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@lsm

lsm commented Sep 16, 2026

Copy link
Copy Markdown
Owner Author

Closing: intentionally parked per #2782, and the branch is preserved as parked/acp-redaction-full-fixed. Revive with the unified permission UX. Branch retained.

@lsm lsm closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant