Repository navigation
Conversation
## What type of PR is this? - [x] fix (bug fix) ## Which issue(s) this PR fixes No linked issue. ## What this PR does / why we need it The credential-reference exceptions could hide literal secrets in default arguments, multiline expressions, or nested assignments. Inspect complete right-hand-side expressions, constrain lookup exceptions to pure lookups, detect numeric literals, and inspect overlapping matches. Database string-column lengths remain exempt from literal-value detection. Regression cases cover quoted and numeric defaults, multiline calls, fallback expressions, and nested assignments. ## Validation - `git diff --check 18106fd..23725db` - `cargo test --locked --offline -p memoria-core --lib sensitivity::tests` — 11 passed. - `cargo test --locked --offline -p memoria-storage --lib fulltext` — 4 passed. Depends on #262 and is stacked on its branch. This diff contains only the follow-up credential-detection change. Merge #262 first, then retarget this PR to `main`. Approved by: @
cfc2874 to
18106fd
Compare
ReviewI checked this out at The PR combines two independent changes: full-text batching and credential heuristics. My comments on each are below. 1. Full-text batching (
|
| Input | Blocked | Expected |
|---|---|---|
password = None |
yes | no |
def login(username, password=None): |
yes | no |
password: str / password: string; |
yes | no |
password = self.password |
yes | no |
password = getpass.getpass("Enter password: ") |
yes | no |
password = request.form.get("password", "") |
yes | no |
Password: must be at least 8 characters |
yes | no |
My secret: I love pineapple pizza |
yes | no |
Bearer bonds were common in the 1920s. |
yes | no |
Use the standard Bearer eyJhbGciOiJIUzI1NiJ9.abc.def header |
no | yes |
a bearer of eyJhbGciOiJIUzI1NiJ9.abc.def |
no | yes |
Very common code patterns are still blocked. Meanwhile, the special cases (standard|flag|torch|pall, of, a|the secret:) look fitted to specific failing samples, and they open small bypasses for real tokens.
There is a bigger design issue as well. A HIGH-tier match blocks the entire memory with 403, which callers treat as non-retryable. For conversation or code ingestion, a single password: str line drops the whole chunk and fails the write. This affects benchmark ingestion directly. Suggestions, in rough priority:
- Make the policy configurable (
block/redact/off) per deployment or per owner. Evaluation and coding workloads need this regardless of how good the heuristics get. - For the HIGH tier, prefer redacting the matched value over blocking the whole memory, so the surrounding context survives.
- If we keep detection, consider detecting by value shape (length, character-class mix, entropy, known prefixes such as
eyJ,ghp_,sk-) instead of enumerating benign syntaxes. That approach generalizes, while syntax allow-lists do not.
There is also a related issue outside this PR's scope. The MEDIUM-tier phone and credit_card regexes redact any 10–19-digit number in place, including IDs, order numbers and millisecond timestamps. That silently changes stored evidence.
Suggestion
I'd be happy to merge the full-text part once there is a DB test, and ideally the cheaper per-batch projection. For the credential part, I'd prefer to discuss the configurable/redact design before investing further in heuristics. Splitting the two would let the full-text fix land independently.
What type of PR is this?
Which issue(s) this PR fixes
No linked issue.
What this PR does / why we need it
Long full-text queries could overwhelm a single database query, and punctuation-only diagnostic tokens could prevent otherwise useful terms from being searched. Batch all distinct terms into groups of 64, merge their lexical scores, and apply the result limit after merging while preserving user and optional retrieval scopes.
Credential detection now distinguishes ordinary prose and source-code references from literal credentials, reducing false-positive ingestion failures. Regression tests cover long-query term preservation, diagnostic underlines, benign references, and credential literals.
Validation
git diff --check e180dff..18106fd23725db, including the follow-up credential fix):cargo test --locked --offline -p memoria-core --lib sensitivity::tests— 11 passed.cargo test --locked --offline -p memoria-storage --lib fulltext— 4 passed.This PR contains only commit
18106fd. The dependent fix is #264, which remains a draft withdo-not-mergeuntil this PR merges intomain. Afterward, rebase #264's single commit ontomain, retarget it tomain, and remove its block. Merge both PRs before deploying.