Adds args_secret_warning(data: dict) -> str | None to bcc_core.py — detects secret-shaped values in args via three paths: bare token-prefix values (e.g. ghp_…), values following a secret-named flag (--token abc), and URLs with embedded user:pass credentials (postgres://user:pass@host/db).
--flag=value inline pairs are intentionally skipped (the flag name already labels the value).
Adds self.secret_warn QLabel to ServerEditor's stdio page; shown/hidden by _check_args() on every field change, hidden on deselect and on stdio→remote type switch. Non-blocking — the save path is not touched.
8 new unit tests in section 10 of test_core.py covering all detection paths and key negatives (benign URLs, env-only secrets, inline flag pairs).
Test plan
python -m pytest — 92 passed
ruff check . — clean
ruff format --check . — clean
GUI smoke-test: core logic is unit-tested; bcc.py wiring done but not smoke-tested in a display environment (per HANDOFF note — no display available in this session)
## Summary
- Adds `args_secret_warning(data: dict) -> str | None` to `bcc_core.py` — detects secret-shaped values in `args` via three paths: bare token-prefix values (e.g. `ghp_…`), values following a secret-named flag (`--token abc`), and URLs with embedded `user:pass` credentials (`postgres://user:pass@host/db`).
- `--flag=value` inline pairs are intentionally skipped (the flag name already labels the value).
- Adds `self.secret_warn` QLabel to `ServerEditor`'s stdio page; shown/hidden by `_check_args()` on every field change, hidden on deselect and on stdio→remote type switch. Non-blocking — the save path is not touched.
- 8 new unit tests in section 10 of `test_core.py` covering all detection paths and key negatives (benign URLs, env-only secrets, inline flag pairs).
## Test plan
- [x] `python -m pytest` — 92 passed
- [x] `ruff check .` — clean
- [x] `ruff format --check .` — clean
- [ ] GUI smoke-test: core logic is unit-tested; `bcc.py` wiring done but not smoke-tested in a display environment (per HANDOFF note — no display available in this session)
Closes #1
Adds `args_secret_warning(data)` to bcc_core — returns a warning string
when any arg positional value looks like a raw credential (token prefix,
value following a secret-named flag, or URL with embedded user:pass like
postgres://user:pass@host). `--flag=value` inline forms are intentionally
skipped (the flag name already labels the value).
Adds `secret_warn` QLabel in ServerEditor's stdio page; shown/hidden by
`_check_args()` on every field change, and cleared on deselect or
stdio→remote type switch. Non-blocking — save path is not touched.
Closes#1
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
the_og
merged commit ece049c993 into main2026-07-02 12:00:16 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
args_secret_warning(data: dict) -> str | Nonetobcc_core.py— detects secret-shaped values inargsvia three paths: bare token-prefix values (e.g.ghp_…), values following a secret-named flag (--token abc), and URLs with embeddeduser:passcredentials (postgres://user:pass@host/db).--flag=valueinline pairs are intentionally skipped (the flag name already labels the value).self.secret_warnQLabel toServerEditor's stdio page; shown/hidden by_check_args()on every field change, hidden on deselect and on stdio→remote type switch. Non-blocking — the save path is not touched.test_core.pycovering all detection paths and key negatives (benign URLs, env-only secrets, inline flag pairs).Test plan
python -m pytest— 92 passedruff check .— cleanruff format --check .— cleanbcc.pywiring done but not smoke-tested in a display environment (per HANDOFF note — no display available in this session)Closes #1