Skip to content

fix(gateway): bound redaction token preprocessing - #742

Merged
dmoliveira merged 1 commit into
mainfrom
fix/redaction-token-validation-safety
Sep 6, 2026
Merged

dmoliveira merged 1 commit into
mainfrom
fix/redaction-token-validation-safety

Conversation

@dmoliveira

Copy link
Copy Markdown
Owner

Summary

  • Reject oversized redaction tokens before trim, byte-length, or detector preprocessing.
  • Preserve invalid oversized configuration values for fail-closed shared validation instead of silently falling back.
  • Add direct ordering regression coverage and regenerate gateway output.

Validation Evidence

  • npm test (967 passing)
  • npm run lint
  • make validate
  • pre-commit run --all-files
  • git diff --check
  • Final static security review: no blocker findings.

@dmoliveira
dmoliveira merged commit 9dd3b1c into main Sep 6, 2026
3 checks passed
@dmoliveira
dmoliveira deleted the fix/redaction-token-validation-safety branch September 6, 2026 05:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant