Potential fix for code scanning alert no. 9: Clear-text storage of sensitive information - #111
Conversation
…nsitive information Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
|
Warning Rate limit exceeded@priyanshujain has exceeded the limit for the number of commits or files that can be reviewed per hour. Please wait 12 minutes and 19 seconds before requesting another review. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. 📒 Files selected for processing (1)
✨ Finishing Touches
🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
CodeRabbit Configuration File (
|
Potential fix for https://github.com/priyanshujain/infragpt/security/code-scanning/9
The best way to fix this clear-text storage of sensitive info is to adopt a "deny by default, allow by exception" approach: always allow-list explicitly the fields that are safe for storage, for every interaction type. This avoids risk from future data changes or insufficient sanitization. The function
log_interactionshould enforce that only whitelisted, non-sensitive fields are persisted for all interaction types. If a new interaction type is introduced, developers must consciously choose which fields to store, avoiding inadvertent logging of secrets likeapi_keyorpassword.Steps:
"agent_conversation_v2": [ ... ].log_interaction, always use this allow-list to filter the sanitized data before logging, regardless of interaction type.Suggested fixes powered by Copilot Autofix. Review carefully before merging.