Skip to content

[Security] Redact HTTP request headers before persisting public artifacts #349

Description

@reacher-z

Problem

The runtime server writes intercepted request headers to requests.jsonl without a default redaction policy. Authorization, Cookie, Set-Cookie, CSRF tokens, and provider credentials can therefore leak into shareable benchmark artifacts.

Required scope

  • Add a default header allowlist or sensitive-header redaction for persisted requests.
  • Redact token-like fields in headers and bounded request bodies where needed.
  • Add an explicit retention/configuration contract and fixture tests.
  • Keep enough metadata to explain that a value was redacted.

Acceptance criteria

  • Secrets in test fixtures never appear in requests.jsonl, summaries, or uploaded artifacts.
  • Redaction behavior is deterministic and covered by tests.
  • Harbor and native paths use the same artifact policy.

This is SEC-002 in docs/codebase-evaluation-2026-09.md. @Perry2004 please review the privacy/retention policy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinghelp wantedExtra attention is needed

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions