feat(DIS-102): sanitizeForDiscord strips paths and tokens before Discord send #46

Merged
dev merged 4 commits from phase-1/sanitize-for-discord into main 2026-04-10 08:05:44 +00:00
Showing only changes of commit 5869c15f9d - Show all commits

View file

@ -13,6 +13,17 @@ export interface SanitizeOptions {
* 3. Discord bot token pattern <redacted>
* 4. Anthropic API key pattern <redacted>
*/
/** Returns both backslash and forward-slash variants of a path (for Windows). */
function pathVariants(p: string): string[] {
const fwd = p.replace(/\\/g, "/");
const bwd = p.replace(/\//g, "\\");
return fwd === bwd ? [p] : [p, fwd, bwd];
}
function replaceAll(text: string, search: string, replacement: string): string {
return text.split(search).join(replacement);
}
export function sanitizeForDiscord(
text: string,
opts: SanitizeOptions = {}
@ -22,12 +33,16 @@ export function sanitizeForDiscord(
// 1. Replace repo root before home so that sub-paths are caught by the
// more specific substitution first (repoRoot is usually inside home).
if (opts.repoRoot) {
result = result.split(opts.repoRoot).join("<disclaw>");
for (const variant of pathVariants(opts.repoRoot)) {
result = replaceAll(result, variant, "<disclaw>");
}
}
// 2. Replace home directory with ~
// 2. Replace home directory with ~ (both slash styles for Windows)
if (opts.home) {
result = result.split(opts.home).join("~");
for (const variant of pathVariants(opts.home)) {
result = replaceAll(result, variant, "~");
}
}
// 3. Discord bot token — format: [MN]<23 base64url>.<6 base64url>.<27 base64url>