Harden credential redaction - #3
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
auth.jsonvalues, including unknownauth_modestrings, from being reflected into visible status fields.Logged in using ChatGPTline before reporting a valid login.Why
A Reddit reviewer correctly identified redaction as the highest-risk claim in the app. The original implementation used three broad regular expressions and did not exercise multiline values, stderr, escaped JSON, malformed auth files, or changed CLI wording. Unknown
auth_modevalues could also be reflected verbatim.User impact
The UI now has substantially stronger defense-in-depth against credential disclosure while preserving useful diagnostic structure. Unsupported authentication modes use fixed localized text instead of displaying untrusted values. Login status is less likely to be spoofed by negative or failing CLI output.
Redaction remains best-effort. Arbitrary same-indentation continuation lines without a structural boundary are intentionally not claimed as covered because consuming them would also hide unrelated diagnostics.
Validation
swift test --scratch-path /tmp/CodexLoginManager-final-tests --disable-index-store -j 1: 45/45 passedRedactorTests: 38/38 passed./script/build_and_run.sh --verifyAPP_BUILD=999 ./script/package_release.sh 1.0.0-beta.2x86_64 arm64architecture verification