Skip to content

fix(engine): redact blocklisted terms in chat-grounding tool_result events - #8960

Closed
joaovictor91123 wants to merge 1 commit into
JSONbored:mainfrom
joaovictor91123:fix/chat-grounding-tool-result-redaction-8869
Closed

fix(engine): redact blocklisted terms in chat-grounding tool_result events#8960
joaovictor91123 wants to merge 1 commit into
JSONbored:mainfrom
joaovictor91123:fix/chat-grounding-tool-result-redaction-8869

Conversation

@joaovictor91123

Copy link
Copy Markdown
Contributor

Summary

  • Apply the same PUBLIC_FIELD_BLOCKLIST redaction used for assistant text chunks to string tool_result content in chat-grounding.
  • Cover the new path in the vitest suite (codecov) and the mirrored engine node:test suite; non-string tool payloads still pass through unchanged.

Closes #8869

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • Full suite not re-run locally (Node 24 vs engines Node 22). Diff is one redaction call site plus unit coverage for the string redaction and non-string passthrough branches; CI is source of truth.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

N/A — no visible UI changes.

Notes

  • Closes a privacy leak where MCP tool output could forward blocklisted fields into the public chat-grounding stream.

…vents

Apply the same PUBLIC_FIELD_BLOCKLIST backstop used for assistant text chunks so MCP tool output cannot leak wallet/trust fields into the public stream.

Closes JSONbored#8869
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 26, 2026
@joaovictor91123

Copy link
Copy Markdown
Contributor Author

Closing to re-open on latest main. CI failed on the same unrelated flake in miner-worktree-allocator-collisions (distinct-path acquire race). chat-grounding-engine.test.ts (39 tests) passed green; one-shot policy forbids a follow-up push.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(engine): chat-grounding tool_result events bypass the privacy redaction backstop

1 participant