惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
量子位
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
美团技术团队
小众软件
小众软件
aimingoo的专栏
aimingoo的专栏
Recent Announcements
Recent Announcements
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
J
Java Code Geeks
V
V2EX
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
博客园 - Franky
爱范儿
爱范儿
T
Tailwind CSS Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
博客园_首页
B
Blog RSS Feed
博客园 - 司徒正美
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(logging): redact persisted transcript text · openclaw...
vincentkoc · 2026-04-27 · via Recent Commits to openclaw:main

@@ -1,6 +1,7 @@

11

import type { AgentMessage } from "@mariozechner/pi-agent-core";

22

import type { SessionManager } from "@mariozechner/pi-coding-agent";

33

import type { OpenClawConfig } from "../config/types.openclaw.js";

4+

import { redactSensitiveText } from "../logging/redact.js";

45

import { getGlobalHookRunner } from "../plugins/hook-runner-global.js";

56

import {

67

applyInputProvenanceToUserMessage,

@@ -16,6 +17,71 @@ export type GuardedSessionManager = SessionManager & {

1617

clearPendingToolResults?: () => void;

1718

};

181920+

function redactTranscriptText(value: string, cfg?: OpenClawConfig): string {

21+

if (cfg?.logging?.redactSensitive === "off") {

22+

return value;

23+

}

24+

return redactSensitiveText(value, {

25+

mode: cfg?.logging?.redactSensitive,

26+

patterns: cfg?.logging?.redactPatterns,

27+

});

28+

}

29+30+

function redactTranscriptContentBlock(block: unknown, cfg?: OpenClawConfig): unknown {

31+

if (!block || typeof block !== "object" || Array.isArray(block)) {

32+

return block;

33+

}

34+

const source = block as Record<string, unknown>;

35+

let next: Record<string, unknown> | null = null;

36+

const assign = (key: string, value: string) => {

37+

const redacted = redactTranscriptText(value, cfg);

38+

if (redacted === value) {

39+

return;

40+

}

41+

next ??= { ...source };

42+

next[key] = redacted;

43+

};

44+45+

if (typeof source.text === "string") {

46+

assign("text", source.text);

47+

}

48+

if (typeof source.thinking === "string") {

49+

assign("thinking", source.thinking);

50+

}

51+

if (typeof source.partialJson === "string") {

52+

assign("partialJson", source.partialJson);

53+

}

54+

return next ?? block;

55+

}

56+57+

function redactTranscriptContent(content: unknown, cfg?: OpenClawConfig): unknown {

58+

if (typeof content === "string") {

59+

return redactTranscriptText(content, cfg);

60+

}

61+

if (!Array.isArray(content)) {

62+

return content;

63+

}

64+

let changed = false;

65+

const redacted = content.map((block) => {

66+

const next = redactTranscriptContentBlock(block, cfg);

67+

changed ||= next !== block;

68+

return next;

69+

});

70+

return changed ? redacted : content;

71+

}

72+73+

function redactTranscriptMessage(message: AgentMessage, cfg?: OpenClawConfig): AgentMessage {

74+

const source = message as unknown as Record<string, unknown>;

75+

const redactedContent = redactTranscriptContent(source.content, cfg);

76+

if (redactedContent === source.content) {

77+

return message;

78+

}

79+

return {

80+

...source,

81+

content: redactedContent,

82+

} as unknown as AgentMessage;

83+

}

84+1985

/**

2086

* Apply the tool-result guard to a SessionManager exactly once and expose

2187

* a flush method on the instance for easy teardown handling.

@@ -38,14 +104,31 @@ export function guardSessionManager(

38104

}

3910540106

const hookRunner = getGlobalHookRunner();

41-

const beforeMessageWrite = hookRunner?.hasHooks("before_message_write")

42-

? (event: { message: import("@mariozechner/pi-agent-core").AgentMessage }) => {

43-

return hookRunner.runBeforeMessageWrite(event, {

44-

agentId: opts?.agentId,

45-

sessionKey: opts?.sessionKey,

46-

});

107+

const beforeMessageWrite = (event: {

108+

message: import("@mariozechner/pi-agent-core").AgentMessage;

109+

}) => {

110+

let message = event.message;

111+

let changed = false;

112+

if (hookRunner?.hasHooks("before_message_write")) {

113+

const result = hookRunner.runBeforeMessageWrite(event, {

114+

agentId: opts?.agentId,

115+

sessionKey: opts?.sessionKey,

116+

});

117+

if (result?.block) {

118+

return result;

47119

}

48-

: undefined;

120+

if (result?.message) {

121+

message = result.message;

122+

changed = true;

123+

}

124+

}

125+

const redacted = redactTranscriptMessage(message, opts?.config);

126+

if (redacted !== message) {

127+

message = redacted;

128+

changed = true;

129+

}

130+

return changed ? { message } : undefined;

131+

};

4913250133

const transform = hookRunner?.hasHooks("tool_result_persist")

51134

? (