fix(02-03): scrub short captured ids only at token boundaries
Numeric seed ids like 1 were substring-replaced through /api/v1 paths and 15-style JSON integers. Keep ReplaceAll for long secrets and isolate short values so the corpus stays replayable. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -456,11 +456,47 @@ func replaceAll(s string, pairs [][2]string) string {
|
||||
if p[0] == "" {
|
||||
continue
|
||||
}
|
||||
s = strings.ReplaceAll(s, p[0], p[1])
|
||||
if len(p[0]) >= 8 {
|
||||
s = strings.ReplaceAll(s, p[0], p[1])
|
||||
continue
|
||||
}
|
||||
s = replaceIsolated(s, p[0], p[1])
|
||||
}
|
||||
return s
|
||||
}
|
||||
|
||||
func replaceIsolated(s, old, neu string) string {
|
||||
if old == "" || s == "" {
|
||||
return s
|
||||
}
|
||||
var b strings.Builder
|
||||
i := 0
|
||||
for i < len(s) {
|
||||
j := strings.Index(s[i:], old)
|
||||
if j < 0 {
|
||||
b.WriteString(s[i:])
|
||||
break
|
||||
}
|
||||
j += i
|
||||
leftOK := j == 0 || !isIdentByte(s[j-1])
|
||||
right := j + len(old)
|
||||
rightOK := right == len(s) || !isIdentByte(s[right])
|
||||
if leftOK && rightOK {
|
||||
b.WriteString(s[i:j])
|
||||
b.WriteString(neu)
|
||||
i = right
|
||||
continue
|
||||
}
|
||||
b.WriteString(s[i : j+len(old)])
|
||||
i = j + len(old)
|
||||
}
|
||||
return b.String()
|
||||
}
|
||||
|
||||
func isIdentByte(c byte) bool {
|
||||
return (c >= '0' && c <= '9') || (c >= 'A' && c <= 'Z') || (c >= 'a' && c <= 'z') || c == '_'
|
||||
}
|
||||
|
||||
func rejectUnclassifiedCredentials(step Step) error {
|
||||
check := func(label, s string) error {
|
||||
if hit := remainingCredential(s); hit != "" {
|
||||
|
||||
Reference in New Issue
Block a user