fix: redact diagnostics config with schema hints (#102426)

This commit is contained in:
Pavan Kumar Gondhi
2026-07-09 20:49:21 +05:30
committed by GitHub
parent baa009e26f
commit 436ed5f308
3 changed files with 69 additions and 1 deletions
@@ -62,6 +62,9 @@ describe("diagnostic support export", () => {
].join(".");
const privateChat = "private user said diagnose my bank transfer";
const webhookBody = "raw webhook body with message contents";
const requestAuthValue = "support-request-auth-value";
const requestTlsPassphrase = "support-request-tls-passphrase";
const proxyTlsPassphrase = "support-proxy-tls-passphrase";
const credentialUrl =
"wss://support-user:support-password@gateway.example/ws?token=short-token&ok=1";
const configPath = path.join(tempDir, "openclaw.json");
@@ -81,6 +84,31 @@ describe("diagnostic support export", () => {
logging: {
redactSensitive: "off",
},
models: {
providers: {
supportProxy: {
baseUrl: "https://models.example.test/v1",
request: {
auth: {
mode: "header",
headerName: "X-Support-Auth",
value: requestAuthValue,
},
tls: {
passphrase: requestTlsPassphrase,
},
proxy: {
mode: "explicit-proxy",
url: "http://127.0.0.1:8080",
tls: {
passphrase: proxyTlsPassphrase,
},
},
},
models: [{ id: "support-model" }],
},
},
},
channels: {
telegram: {
accounts: {
@@ -264,6 +292,10 @@ describe("diagnostic support export", () => {
expect(combined).not.toContain("QWxhZGRpbjpvcGVuIHNlc2FtZQ==");
expect(combined).not.toContain("sid=secret");
expect(combined).not.toContain("structured secret payload");
expect(combined).not.toContain(requestAuthValue);
expect(combined).not.toContain(requestTlsPassphrase);
expect(combined).not.toContain(proxyTlsPassphrase);
expect(combined).not.toContain("__OPENCLAW_REDACTED__");
expect(combined).not.toContain("gateway-session-15555551212");
expect(combined).not.toContain("supportEventSecret");
expect(combined).not.toContain(fakeAwsKey);
@@ -365,6 +397,25 @@ describe("diagnostic support export", () => {
redactSensitive?: string;
};
agents?: Array<{ name?: string; instructions?: string }>;
models?: {
providers?: {
supportProxy?: {
request?: {
auth?: {
value?: string;
};
tls?: {
passphrase?: string;
};
proxy?: {
tls?: {
passphrase?: string;
};
};
};
};
};
};
};
expect(sanitizedConfig.gateway).toEqual({
mode: "local",
@@ -376,6 +427,15 @@ describe("diagnostic support export", () => {
},
});
expect(sanitizedConfig.logging?.redactSensitive).toBe("off");
expect(sanitizedConfig.models?.providers?.supportProxy?.request?.auth?.value).toBe(
"<redacted>",
);
expect(sanitizedConfig.models?.providers?.supportProxy?.request?.tls?.passphrase).toBe(
"<redacted>",
);
expect(sanitizedConfig.models?.providers?.supportProxy?.request?.proxy?.tls?.passphrase).toBe(
"<redacted>",
);
expect(Object.keys(sanitizedConfig.channels?.telegram?.accounts ?? {})).toEqual([
"<redacted-account-1>",
]);
+5 -1
View File
@@ -6,6 +6,7 @@ import { asOptionalRecord } from "@openclaw/normalization-core/record-coerce";
import { parseConfigJson5 } from "../config/io.js";
import { resolveConfigPath, resolveStateDir } from "../config/paths.js";
import { redactConfigObject } from "../config/redact-snapshot.js";
import { buildConfigSchema } from "../config/schema.js";
import { resolveHomeRelativePath } from "../infra/home-dir.js";
import { VERSION } from "../version.js";
import {
@@ -291,7 +292,10 @@ function sanitizeConfigShape(
}
function sanitizeConfigDetails(parsed: unknown, redaction: SupportRedactionContext): unknown {
return sanitizeSupportConfigValue(redactConfigObject(parsed), redaction);
return sanitizeSupportConfigValue(
redactConfigObject(parsed, buildConfigSchema().uiHints),
redaction,
);
}
function configShapeReadFailure(params: {
@@ -2,6 +2,7 @@
import path from "node:path";
import { isSensitiveUrlQueryParamName } from "@openclaw/net-policy/redact-sensitive-url";
import { asOptionalRecord } from "@openclaw/normalization-core/record-coerce";
import { REDACTED_SENTINEL } from "../config/redact-snapshot.js";
import { isSecretRefShape } from "../config/redact-snapshot.secret-ref.js";
import { isBlockedObjectKey } from "../infra/prototype-keys.js";
import { redactSensitiveText } from "./redact.js";
@@ -429,6 +430,9 @@ export function sanitizeSupportConfigValue(
return isPrivateConfigField(key) ? "<redacted>" : value;
}
if (typeof value === "string") {
if (value === REDACTED_SENTINEL) {
return "<redacted>";
}
return isPrivateConfigField(key) ? "<redacted>" : redactSupportString(value, redaction);
}
if (depth >= MAX_SUPPORT_SNAPSHOT_DEPTH) {