feat(security): migrate sha1 hashes to sha256 for synthetic ids (#7343) (#22528)

* feat(prompt): add explicit owner hash secret to obfuscation path

* feat(security): migrate synthetic IDs to sha256 for #7343
This commit is contained in:
Vincent Koc
2026-02-21 03:20:14 -05:00
committed by GitHub
parent 9abab6a2c9
commit c20d519e05
6 changed files with 11 additions and 9 deletions

View File

@@ -1,5 +1,5 @@
import { createHash } from "node:crypto";
import type { AgentMessage } from "@mariozechner/pi-agent-core";
import { createHash } from "node:crypto";
export type ToolCallIdMode = "strict" | "strict9";
@@ -94,7 +94,7 @@ export function isValidCloudCodeAssistToolId(id: string, mode: ToolCallIdMode =
}
function shortHash(text: string, length = 8): string {
return createHash("sha1").update(text).digest("hex").slice(0, length);
return createHash("sha256").update(text).digest("hex").slice(0, length);
}
function makeUniqueToolId(params: { id: string; used: Set<string>; mode: ToolCallIdMode }): string {