feat(codex): support agent identity accounts

This commit is contained in:
AAEE86
2026-07-21 20:58:49 +08:00
parent 7756c0913f
commit b61c590bdb
20 changed files with 1763 additions and 17 deletions
+27 -3
View File
@@ -81,8 +81,10 @@ static ACCESS_TOKEN_REGEX: LazyLock<Regex> = LazyLock::new(|| {
.expect("access token regex should compile")
});
static SECRET_KEY_REGEX: LazyLock<Regex> = LazyLock::new(|| {
Regex::new(r#"(?i)\bsecret[_-]?key\s*[:=]\s*["']?[A-Za-z0-9._~+/=-]{20,}"#)
.expect("secret key regex should compile")
Regex::new(
r#"(?i)\b(?:secret|agent[_-]?private)[_-]?key\s*[:=]\s*["']?[A-Za-z0-9._~+/=-]{20,}"#,
)
.expect("secret key regex should compile")
});
static HIGH_ENTROPY_TOKEN_REGEX: LazyLock<Regex> =
LazyLock::new(|| Regex::new(r"\b[A-Za-z0-9_-]{32,}\b").expect("api key regex should compile"));
@@ -3528,7 +3530,13 @@ fn detect_candidates_with_probe(
is_valid_named_token,
);
}
if input.contains("secret_key") || input.contains("secret-key") || input.contains("SecretKey") {
if input.contains("secret_key")
|| input.contains("secret-key")
|| input.contains("SecretKey")
|| input.contains("agent_private_key")
|| input.contains("agent-private-key")
|| input.contains("agentPrivateKey")
{
push_regex_candidates(
input,
&SECRET_KEY_REGEX,
@@ -4414,6 +4422,22 @@ mod tests {
);
}
#[test]
fn pii_redaction_hides_agent_identity_private_keys() {
let private_key =
"agent_private_key=MC4CAQAwBQYDK2VwBCIEIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA";
let mut session = session_at(601);
let redacted = session.redact_text(private_key);
assert!(!redacted.text.contains(private_key));
assert!(redacted.text.contains("<AETHER:SECRET_KEY:"));
assert!(redacted
.matches
.iter()
.any(|matched| matched.kind == Some(RedactionKind::SecretKey)));
}
#[test]
fn pii_redaction_session_uses_configured_sentinel_namespace() {
let mut session = RedactionSession::new(