Skip to content

fix(opencode): redact credentials in debug config - #50956

Merged
rekram1-node merged 2 commits into
devfrom
debug-redaction-v1
Sep 23, 2026
Merged

rekram1-node merged 2 commits into
devfrom
debug-redaction-v1

Conversation

@opencode-agent

@opencode-agent opencode-agent Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Closes #50915

Always redact credential-named config values, all configured HTTP header values, and credential-bearing URLs in opencode debug config. Preserve unrelated settings and the live resolved config. Full *** masks avoid exposing fragments of short keys. There is no unmasking flag; this is not a general-purpose secret scanner for arbitrary user strings.

Tests: bun test test/cli/debug-config.test.ts --timeout 90000; bun typecheck (from packages/opencode).

Requested by: @rekram1-node (Aiden via Slack)

@rekram1-node
rekram1-node merged commit 82d4c89 into dev Sep 23, 2026
10 of 12 checks passed
@rekram1-node
rekram1-node deleted the debug-redaction-v1 branch September 23, 2026 22:35
jinjunnn added a commit to jinjunnn/alpha-code that referenced this pull request Sep 24, 2026
`57646831b` 这次 sync 把两条上游改动带进 alpha,各打红一道本机闸门。今晚三条
独立 lane(`#1433` / `#1445` / `#1448`)各自撞上同一对红,全都 push 不出去 ——
这不是谁的改动坏了,是 base 本身红。

**一、`debug config` 现在给凭证打码**

上游 `82d4c8903 fix(opencode): redact credentials in debug config (anomalyco#50956)` 起,
`redactConfig()` 会把 `headers` 下的每个字符串值换成 `"***"`,且**没有开关**
(`packages/opencode/src/cli/cmd/debug/redact.ts`;同一 commit 顺带删掉了
`builder: (yargs) => yargs`)。

`mcp-server-derivation.test.ts` 的 ③ 那一格用 `debug config` 读回真引擎合并后的
配置,于是断言 `X-Token: "t"` 恒红。

**改成断言脱敏后的形状,而不是把这一格删掉或放宽**:

- 这一格真正要判的是「连接字段以真源为准」—— 靠的是 `url`(真源 `mcp.example.com`
  压过 XDG 的 `user-global.example`),而 `redactConfig` 只在 URL 带用户名/口令/
  敏感 query 时才动 url,这里逐字未脱敏,判据完好;
- 头部的**真实值**在 ① 那一格仍被逐字断言,那一格读的是我们自己的注入面、不经引擎。
  所以「值有没有原样传下去」并没有因为这次改动失去判官。

**二、`transform.test.ts` 的用例数被上游加了 24 条**

登记 561,实测 585。`git diff 5764683^1 5764683` 对该文件**纯增量**(零条
`test(` / `it(` 被删),与前两次同步的形态一致(368 → 411 → 561)。按脚本自己的
`--update` 写回,all-or-nothing,diff 恰好一行。

Co-authored-by: jinjunnn <slmbaovanetti99@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
rldona pushed a commit to rldona/FlupCode that referenced this pull request Sep 24, 2026
Co-authored-by: rekram1-node <rekram1-node@users.noreply.github.com>
pminevp pushed a commit to AxsionDev/Lunos that referenced this pull request Sep 27, 2026
Brings Lunos up to date with anomalyco/opencode dev @ b471c2b (63 commits, 9 days).

Conflicts resolved:
- 29 package.json files: Lunos's version lines (1.18.40) and VS Code extension identity; upstream's
  dependency bumps (@ai-sdk/togetherai 2.0.68, gitlab-ai-provider 6.18.0, open 11.0.4) kept.
- debug/config.ts: upstream's credential redaction (anomalyco#50956) combined with Lunos's drain-safe
  output (XCOD-77) and --sources (XCOD-102).
- triage.yml, duplicate-issues.yml: stay deleted (XCOD-18).
- docs/ecosystem.mdx: upstream's (the Lunos docs build excludes this page, XCOD-124).
- bun.lock: regenerated; nix/hashes.json: Lunos's, recomputed by nix-hashes on dev.
- lunos.upstreamVersion 1.18.32, upstreamSync stamped (0 days behind at this commit).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Jovan1666 pushed a commit to Jovan1666/opencode that referenced this pull request Oct 4, 2026
Co-authored-by: rekram1-node <rekram1-node@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FEATURE REQUEST]: Redact credential values in opencode debug config

1 participant