feat: parameterize sensitive recorded inputs#1369
Conversation
Size Report
Startup median (7 runs, lower is better):
Top changed chunks:
|
|
Needs changes at
CI is green, but the current provider scenario is mocked. After fixes, provide live simulator/device evidence that a parameterized fill executes the literal while the response, session state/events, diagnostics, temp/target |
|
Addressed all three review findings in ff980e9:
Validation:
Live iOS simulator evidence: recorded a Settings Search fill with |
|
Re-review at |
|
Addressed the remaining blocker in d8f0071.
Validation: |
|
P1 — Arbitrary backend output can still retain the literal. At The new response/settle regressions are meaningful for delimiter-separated echoes, but they do not cover concatenated strings or keys. Please scrub every literal occurrence in untrusted backend/settle output and keys while preserving only explicitly structural provenance, then add production-route regressions for concatenated, prefix/suffix, and object-key echoes. Live evidence still does not exercise this leak path. |
|
Addressed the new P1 in 8af3931.
Validation: focused handler/recorder/replay tests 14/14, provider scenario 3/3, format, lint, typecheck, layering, fallow, MCP metadata, and build passed. The bounded full coverage run passed 541 files and 4,583/4,583 tests. |
|
Re-reviewed exact head
The prior non-whitespace concatenation/key leak is otherwise fixed, structural trust is path-specific, and current provider/handler regressions are meaningful for their covered inputs. All exact-head checks are green. No ready label. |
Summary
fill --record-as <VAR>authoring contract across CLI, Node, and MCP surfaces${VAR}in session state, diagnostics, target evidence, and published.adscriptsCloses #1348
Validation
pnpm check:quickpnpm check:fallow --base origin/mainpnpm exec vitest run --project provider-integration --maxWorkers=4(144 passed)pnpm test:integration:node(15 passed, 6 live-only tests skipped)pnpm test:integration:progress:checkSkillGym was not completed locally because its external model runners were unavailable from the sandbox.