Skip to content

fix(gateway): close remaining redaction boundaries - #743

Merged
dmoliveira merged 1 commit into
mainfrom
fix/provider-redaction-final-boundary
Sep 6, 2026
Merged

dmoliveira merged 1 commit into
mainfrom
fix/provider-redaction-final-boundary

Conversation

@dmoliveira

Copy link
Copy Markdown
Owner

Summary

  • Fail closed when a contextual detector still matches after a replacement that leaves the value unchanged.
  • Bound provider fallback session-ID extraction by the configured message limit and run it inside the guarded finalizer path.
  • Preserve direct system prompt strings as mutable while scanning system objects from root-scan mode.

Validation Evidence

  • npm test (968 passing)
  • npm run lint
  • make validate
  • pre-commit run --all-files
  • git diff --check
  • Final static review: no blockers for this slice.

Follow-up

  • Custom JavaScript regex execution isolation is tracked separately in Codememory task_157.

@dmoliveira
dmoliveira merged commit d09e9b3 into main Sep 6, 2026
3 checks passed
@dmoliveira
dmoliveira deleted the fix/provider-redaction-final-boundary branch September 6, 2026 06:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant