DIS-003: sanitizedEnv() � Secrets aus Child-Env entfernen #1
Labels
No labels
blocked
needs-review
phase:0
phase:1
phase:1.5
phase:2
phase:3
phase:4
phase:5
phase:6+
priority:p0
priority:p1
priority:p2
security
type:chore
type:ci
type:docs
type:feat
type:fix
type:idea
type:known-issue
type:refactor
type:test
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: dev/disclaw#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Ziel
Kein Secret (
DISCORD_BOT_TOKENetc.) im Environment desclaude-Kindprozesses. Heute exfiltrierbar viaecho $DISCORD_BOT_TOKEN.Kontext
runner.tsvererbt aktuellprocess.envvollst�ndig.?
docs/development-plan.md�2.6Scope
In:
src/runtime/env.ts:sanitizedEnv(extra?)entfernt Token/Secret-Pattern, setztCI=true,DISCLAW_AGENT=1� optionaleenv_blocklistviadisclaw.yaml� Runner nutztsanitizedEnvOut: Whitelist-Modus
Definition of Done
sanitizedEnv()ist pur, keine Seiteneffektetests/unit/sanitize-env.test.tsdeckt alle Pattern-CasessanitizedEnvan allen Spawn-Stellennpm run build && npm testgr�nBranch
phase-0/sanitize-envAbh�ngigkeiten
Keine. Kann parallel zu DIS-002 laufen.