Skip to content

fix(security): sanitize quoted passwords and tokens containing spaces in SandboxSanitizer (#918) - #949

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/918-sandbox-sanitizer-quoted-secrets
Sep 25, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/918-sandbox-sanitizer-quoted-secrets

Conversation

@ZhuchkaTriplesix

Copy link
Copy Markdown
Member

Closes #918

Summary of Changes

  • Updated _passwordAssignment regex in SandboxSanitizer to distinguish quoted strings (both single and double quotes, supporting spaces and escaped quotes) from unquoted tokens, and handle optional quotes around assignment keys.
  • Updated sanitize() mapping logic to preserve quotes around redacted tokens when input values are quoted.
  • Added comprehensive unit tests in sandbox_sanitization_pipe_test.dart covering multi-word single- and double-quoted secrets, escaped quotes, and unquoted values.

@github-actions github-actions Bot added bug Something isn't working marketplace Extensions marketplace, ExtensionManifest core Core library logic and services labels Sep 25, 2026
@github-actions github-actions Bot added this to the 0.4.18 milestone Sep 25, 2026
@ZhuchkaTriplesix
ZhuchkaTriplesix merged commit d508a4f into dev Sep 25, 2026
4 checks passed
@ZhuchkaTriplesix
ZhuchkaTriplesix deleted the issue/918-sandbox-sanitizer-quoted-secrets branch September 28, 2026 08:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working core Core library logic and services marketplace Extensions marketplace, ExtensionManifest

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant