mirror of https://github.com/garrytan/gstack.git
Security: redact sensitive values from command output
Prevent secrets and sensitive data from leaking into stdout and model transcripts by redacting output from type, cookie, header, forms, and storage commands. Fixes #18 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
1b317aae9a
commit
6c5fefc846
|
|
@ -65,7 +65,7 @@ export async function handleReadCommand(
|
||||||
id: input.id || undefined,
|
id: input.id || undefined,
|
||||||
placeholder: input.placeholder || undefined,
|
placeholder: input.placeholder || undefined,
|
||||||
required: input.required || undefined,
|
required: input.required || undefined,
|
||||||
value: input.value || undefined,
|
value: input.type === 'password' ? '[redacted]' : (input.value || undefined),
|
||||||
options: el.tagName === 'SELECT'
|
options: el.tagName === 'SELECT'
|
||||||
? [...(el as HTMLSelectElement).options].map(o => ({ value: o.value, text: o.text }))
|
? [...(el as HTMLSelectElement).options].map(o => ({ value: o.value, text: o.text }))
|
||||||
: undefined,
|
: undefined,
|
||||||
|
|
@ -184,7 +184,7 @@ export async function handleReadCommand(
|
||||||
const key = args[1];
|
const key = args[1];
|
||||||
const value = args[2] || '';
|
const value = args[2] || '';
|
||||||
await page.evaluate(([k, v]) => localStorage.setItem(k, v), [key, value]);
|
await page.evaluate(([k, v]) => localStorage.setItem(k, v), [key, value]);
|
||||||
return `Set localStorage["${key}"] = "${value}"`;
|
return `Set localStorage["${key}"]`;
|
||||||
}
|
}
|
||||||
const storage = await page.evaluate(() => ({
|
const storage = await page.evaluate(() => ({
|
||||||
localStorage: { ...localStorage },
|
localStorage: { ...localStorage },
|
||||||
|
|
|
||||||
|
|
@ -94,7 +94,7 @@ export async function handleWriteCommand(
|
||||||
const text = args.join(' ');
|
const text = args.join(' ');
|
||||||
if (!text) throw new Error('Usage: browse type <text>');
|
if (!text) throw new Error('Usage: browse type <text>');
|
||||||
await page.keyboard.type(text);
|
await page.keyboard.type(text);
|
||||||
return `Typed "${text}"`;
|
return `Typed ${text.length} characters`;
|
||||||
}
|
}
|
||||||
|
|
||||||
case 'press': {
|
case 'press': {
|
||||||
|
|
@ -153,7 +153,7 @@ export async function handleWriteCommand(
|
||||||
domain: url.hostname,
|
domain: url.hostname,
|
||||||
path: '/',
|
path: '/',
|
||||||
}]);
|
}]);
|
||||||
return `Cookie set: ${name}=${value}`;
|
return `Cookie set: ${name}=****`;
|
||||||
}
|
}
|
||||||
|
|
||||||
case 'header': {
|
case 'header': {
|
||||||
|
|
@ -163,7 +163,9 @@ export async function handleWriteCommand(
|
||||||
const name = headerStr.slice(0, sep).trim();
|
const name = headerStr.slice(0, sep).trim();
|
||||||
const value = headerStr.slice(sep + 1).trim();
|
const value = headerStr.slice(sep + 1).trim();
|
||||||
await bm.setExtraHeader(name, value);
|
await bm.setExtraHeader(name, value);
|
||||||
return `Header set: ${name}: ${value}`;
|
const sensitiveHeaders = ['authorization', 'cookie', 'set-cookie', 'x-api-key', 'x-auth-token'];
|
||||||
|
const redactedValue = sensitiveHeaders.includes(name.toLowerCase()) ? '****' : value;
|
||||||
|
return `Header set: ${name}: ${redactedValue}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
case 'useragent': {
|
case 'useragent': {
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue