fix: sanitize LLM errors and clean up low-priority findings - #58
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b2b82dbd11
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| def _on_worker_error(self, err_msg: str) -> None: | ||
| logger.error("Worker error: %s", err_msg) | ||
| self._finish_worker_with_error(err_msg, "worker error") | ||
| logger.debug("Raw worker error: %s", err_msg) |
There was a problem hiding this comment.
Avoid logging unsanitized provider errors in debug mode
When BLITZTEXT_DEBUG is enabled, this writes the complete external exception to stderr before sanitization, including any API keys, bearer tokens, URL credentials, control characters, or unbounded provider response content that the new sanitizer is intended to suppress. Debug output is commonly captured for troubleshooting and shared, so sanitize this record as well (or omit it) rather than preserving the raw error.
Useful? React with 👍 / 👎.
Zusammenfassung
Folge-PR zu #57 (Restpunkte aus dem Sicherheitsaudit nach PR #56):
sanitize_external_error()bereinigt: Steuerzeichen entfernt, bekannte Secret-Muster (Bearer-Token inkl. Unicode-verschleierter Trennzeichen,sk--Keys,api_key/token/secret/password-Zuweisungen, URL-Credentials) maskiert, auf 240 Zeichen begrenzt. Der vollständige Rohtext bleibt ausschließlich im DEBUG-Log.app/i18n.pyvon ASCII-Umschreibungen (verfuegbar,bestaetigt,unterstuetzt,zusammengefuehrt,Moechtest) auf echte Umlaute korrigiert. Keys und Platzhalter unverändert._is_terminal_active()inapp/paste_service.pyentfernt (nur noch von eigenen Tests genutzt, Produktionspfad nutzt die Logik bereits inline in_ydotool_paste).Verifikation
QT_QPA_PLATFORM=offscreen WHISPER_GUI_TESTS=1 .venv/bin/python -m pytest tests/ -q→ 588 passed, 2 skipped, 0 failedgit diff --check origin/main...HEAD→ sauberNicht im Scope
README.de.md— erfordert reale GUI-Screenshot-Aufnahme, bleibt offener manueller Punkt.Kein Merge durch diesen PR-Ersteller-Workflow — Merge-Entscheidung bei Tim.