mirror of
https://github.com/openclaw/openclaw.git
synced 2026-05-10 10:55:07 +00:00
perf(security): bound regex input in filters and redaction
This commit is contained in:
@@ -102,6 +102,15 @@ describe("redactSensitiveText", () => {
|
||||
expect(output).toBe(input);
|
||||
});
|
||||
|
||||
it("redacts large payloads with bounded regex passes", () => {
|
||||
const input = `${"x".repeat(40_000)} OPENAI_API_KEY=sk-1234567890abcdef ${"y".repeat(40_000)}`;
|
||||
const output = redactSensitiveText(input, {
|
||||
mode: "tools",
|
||||
patterns: defaults,
|
||||
});
|
||||
expect(output).toContain("OPENAI_API_KEY=sk-123…cdef");
|
||||
});
|
||||
|
||||
it("skips redaction when mode is off", () => {
|
||||
const input = "OPENAI_API_KEY=sk-1234567890abcdef";
|
||||
const output = redactSensitiveText(input, {
|
||||
|
||||
Reference in New Issue
Block a user