Skip to content

Commit d3fb76b

Browse files
committed
refactor(dsh-loopx-plugin): simplify observer safety patterns
Signed-off-by: song <liusongstep@gmail.com>
1 parent f0b58f6 commit d3fb76b

1 file changed

Lines changed: 19 additions & 6 deletions

File tree

‎packages/dsh-loopx-plugin/src/observer.ts‎

Lines changed: 19 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -69,8 +69,19 @@ export const RUN_IDENTITY_FIELDS = [
6969

7070
const IDENTITY_TOKEN = /^[A-Za-z0-9][A-Za-z0-9_.:-]{0,120}$/u
7171
const SUMMARY_TOKEN = /^[A-Za-z0-9][A-Za-z0-9_./:-]{0,79}$/u
72-
const LOCAL_PATH_SURFACE = /(?<![:/A-Za-z0-9])(?:\/(?:Users|home|Volumes|private|tmp|var|etc|opt|srv|mnt|root|workspace|workspaces)\/[^\s`'"<>]+|[A-Za-z]:[\\/](?:Users|Documents and Settings)[\\/][^\s`'"<>]+)/iu
73-
const SECRET_LIKE_SURFACE = /(?:\bbearer\s+[a-z0-9._~+\/=-]{16,}|\b(?:access|secret)[_-]?key\s*[=:]\s*[^\s`'"<>]+|\b(?:ak|sk)\s*[=:]\s*[^\s`'"<>]+|(?<![a-z0-9_])(?:ak|sk)[-_=:][a-z0-9_=-]{10,}|\bgh[pousr]_[a-z0-9]{20,}\b|\beyj[a-z0-9_-]{10,}\.[a-z0-9_-]{10,}\.[a-z0-9_-]{10,}\b|\btoken\s*[=:]\s*[^\s`'"<>]{12,})/iu
72+
const LOCAL_PATH_SURFACES = [
73+
/(?<![:/a-z0-9])\/(?:users|home|volumes|private|tmp|var|etc|opt|srv|mnt|root|workspace|workspaces)\/[^\s`'"<>]+/iu,
74+
/(?<![:/a-z0-9])[a-z]:[/\\](?:users|documents and settings)[/\\][^\s`'"<>]+/iu,
75+
] as const
76+
const SECRET_LIKE_SURFACES = [
77+
/\bbearer\s+[a-z0-9._~+/=-]{16,}/iu,
78+
/\b(?:access|secret)[_-]?key\s*[=:]\s*[^\s`'"<>]+/iu,
79+
/\b(?:ak|sk)\s*[=:]\s*[^\s`'"<>]+/iu,
80+
/(?<![a-z0-9_])(?:ak|sk)[-_=:][a-z0-9_=-]{10,}/iu,
81+
/\bgh[pousr]_[a-z0-9]{20,}\b/iu,
82+
/\beyj[a-z0-9_-]{10,}\.[a-z0-9_-]{10,}\.[a-z0-9_-]{10,}\b/iu,
83+
/\btoken\s*[=:]\s*[^\s`'"<>]{12,}/iu,
84+
] as const
7485
const CREDENTIAL_FIELD_FAMILIES = new Set([
7586
'accesskey', 'accesstoken', 'apikey', 'authtoken', 'authorization',
7687
'clientsecret', 'cookie', 'credential', 'credentials', 'password',
@@ -176,15 +187,17 @@ export interface ShadowObserverOptions {
176187
}
177188

178189
function normalizePublicSafeFieldName(value: string): string {
179-
return value
190+
const normalized = value
180191
.replace(/([a-z0-9])([A-Z])/gu, '$1_$2')
181-
.replace(/[^A-Za-z0-9]+/gu, '_')
182-
.replace(/^_+|_+$/gu, '')
192+
.replace(/[^a-z0-9]+/giu, '_')
183193
.toLowerCase()
194+
const withoutLeading = normalized.startsWith('_') ? normalized.slice(1) : normalized
195+
return withoutLeading.endsWith('_') ? withoutLeading.slice(0, -1) : withoutLeading
184196
}
185197

186198
function isPublicSafeText(value: string): boolean {
187-
return !LOCAL_PATH_SURFACE.test(value) && !SECRET_LIKE_SURFACE.test(value)
199+
return !LOCAL_PATH_SURFACES.some(pattern => pattern.test(value))
200+
&& !SECRET_LIKE_SURFACES.some(pattern => pattern.test(value))
188201
}
189202

190203
/** Keep the producer boundary equivalent to LoopX's recursive Python guard. */

0 commit comments

Comments
 (0)