修复:Bearer 引号值脱敏正则只匹配到第一个空格,密钥尾部漏出

- directThreadSanitize.ts:BEARER_VALUE 的引号分支由 \\.?["'] 改为 \\?["'],与同文件 SENSITIVE_ASSIGNMENT 的写法一致
- 原写法要求引号前必须有一个字面反斜杠,导致 Bearer "abc def" 走不到引号分支,退化到裸 token 分支后只遮到第一个空格,示例会输出 Bearer [redacted-secret] def"
- 修正后引号内的整段值都被遮掉;JSON 转义的 \"abc def\" 仍然匹配
- 同步在 directThreadSanitize.test.ts 增加带引号 Bearer 的用例(修复前该用例失败)
This commit is contained in:
2026-10-03 13:42:40 +08:00
parent 0a16d5d574
commit d07f894bf6
2 changed files with 5 additions and 1 deletions
@@ -431,7 +431,7 @@ const SENSITIVE_ASSIGNMENT = new RegExp(
);
const BEARER_VALUE =
/(\bbearer\b)(\s+)((?:\\.?["'][^"']*\\.?["'])|(?:<[^>]*>)|(?:\[[^\]]*\])|(?:[^\s,;,;&\]})<>]+))/gi;
/(\bbearer\b)(\s+)((?:\\?["'][^"']*\\?["'])|(?:<[^>]*>)|(?:\[[^\]]*\])|(?:[^\s,;,;&\]})<>]+))/gi;
const CONFIG_NAMES = /(?:\.env|game-creator\.config)[^\s'"`,;::&\]})<>]*/gi;
@@ -56,6 +56,10 @@ describe('directThreadSanitize', () => {
expect(sanitizeDirectThreadText(ROOT, 'h x Bearer abc123 y')).toBe(
'h x Bearer [redacted-secret] y',
);
// 带引号的 Bearer 值(含空格)也要整段遮掉,不能只遮到第一个空格。
expect(sanitizeDirectThreadText(ROOT, 'h x Bearer "abc def" y')).toBe(
'h x Bearer [redacted-secret] y',
);
});
it('.env / game-creator.config 换成配置占位符', () => {