fix(DIS-102): handle both slash styles for Windows path sanitization
Some checks failed
CI / build-and-test (ubuntu-latest) (pull_request) Has been cancelled
CI / build-and-test (windows-latest) (pull_request) Has been cancelled
CI / lint (pull_request) Has been cancelled

os.homedir() returns backslashes on Windows but Claude Code outputs
paths with forward slashes. Replace both C:\Users\x and C:/Users/x
variants so home and repoRoot are always redacted.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Nick Tabeling 2026-04-10 09:58:34 +02:00
parent 90f96bdbf4
commit 5869c15f9d

View file

@ -13,6 +13,17 @@ export interface SanitizeOptions {
* 3. Discord bot token pattern <redacted>
* 4. Anthropic API key pattern <redacted>
*/
/** Returns both backslash and forward-slash variants of a path (for Windows). */
function pathVariants(p: string): string[] {
const fwd = p.replace(/\\/g, "/");
const bwd = p.replace(/\//g, "\\");
return fwd === bwd ? [p] : [p, fwd, bwd];
}
function replaceAll(text: string, search: string, replacement: string): string {
return text.split(search).join(replacement);
}
export function sanitizeForDiscord(
text: string,
opts: SanitizeOptions = {}
@ -22,12 +33,16 @@ export function sanitizeForDiscord(
// 1. Replace repo root before home so that sub-paths are caught by the
// more specific substitution first (repoRoot is usually inside home).
if (opts.repoRoot) {
result = result.split(opts.repoRoot).join("<disclaw>");
for (const variant of pathVariants(opts.repoRoot)) {
result = replaceAll(result, variant, "<disclaw>");
}
}
// 2. Replace home directory with ~
// 2. Replace home directory with ~ (both slash styles for Windows)
if (opts.home) {
result = result.split(opts.home).join("~");
for (const variant of pathVariants(opts.home)) {
result = replaceAll(result, variant, "~");
}
}
// 3. Discord bot token — format: [MN]<23 base64url>.<6 base64url>.<27 base64url>