Skip to content

Redact sensitive fields from diagnostics bundles#4454

Open
Thanhdn1984 wants to merge 1 commit into
orchestration-agent:mainfrom
Thanhdn1984:susan/diagnostics-redaction-4453
Open

Redact sensitive fields from diagnostics bundles#4454
Thanhdn1984 wants to merge 1 commit into
orchestration-agent:mainfrom
Thanhdn1984:susan/diagnostics-redaction-4453

Conversation

@Thanhdn1984
Copy link
Copy Markdown

Fixes #4453.

Scope:

  • adds recursive diagnostics redaction for token/secret/password/credential keys
  • limits environment diagnostics to approved operational metadata only
  • covers representative config and connector payloads, including nested list/tuple data

Validation:

  • PYTHONDONTWRITEBYTECODE=1 uv run pytest tests/test_diagnostics.py -q -p no:cacheprovider -> 3 passed
  • git diff --check -> passed

No secrets, tokens, hidden context, or private runtime data included.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[ Bounty $8k ] [ Security ] Remove sensitive fields from health diagnostics — support diagnostics bundle

1 participant