mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
test: add regression guard for chat title masking (#24584)
Follow-up to #24564 addressing unresolved review findings. - **DEREM-1**: Add `Test_diff/Chat/TitleMasked` to `enterprise/audit/diff_internal_test.go` so flipping `title` back to `ActionTrack` fails loudly. Verified: the case passes today, fails with a clear diff after flipping to `ActionTrack`, passes again after reverting. - **DEREM-4**: Inline comment at `coderd/audit/request.go:138` explaining why `ResourceTarget` for `database.Chat` returns a UUID prefix instead of the title. - **DEREM-5**: Trailing comment on `enterprise/audit/table.go` `title` entry, matching the surrounding `ActionSecret` comment style. Won't-fix, with rationale (per user): - **DEREM-2** (8-char prefix collision risk): `resource_target` is a display hint, not an identifier; the full UUID lives in `resource_id`. - **DEREM-3** (named constant for `[:8]`): single call site; extracting would be ceremony. - **DEREM-6** (PR title misleading): merged PR title is immutable. - **DEREM-7** (historical log redaction): the offending version only shipped to dogfood for a couple of hours and not to customers. > 🤖
This commit is contained in:
@@ -135,6 +135,12 @@ func ResourceTarget[T Auditable](tgt T) string {
|
||||
case database.AiSeatState:
|
||||
return "AI Seat"
|
||||
case database.Chat:
|
||||
// Chat titles can contain sensitive content (secrets, internal
|
||||
// project names), so we use a short UUID prefix as a display
|
||||
// hint instead. The full UUID is still recorded in resource_id,
|
||||
// which is what the audit UI links on. An 8-char prefix is fine
|
||||
// for display; collisions affect the display label and search
|
||||
// filter but not the primary resource identifier.
|
||||
return typed.ID.String()[:8]
|
||||
default:
|
||||
panic(fmt.Sprintf("unknown resource %T for ResourceTarget", tgt))
|
||||
|
||||
@@ -4,10 +4,12 @@ import (
|
||||
"context"
|
||||
"testing"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/require"
|
||||
"go.opentelemetry.io/otel/propagation"
|
||||
|
||||
"github.com/coder/coder/v2/coderd/audit"
|
||||
"github.com/coder/coder/v2/coderd/database"
|
||||
)
|
||||
|
||||
func TestBaggage(t *testing.T) {
|
||||
@@ -31,3 +33,15 @@ func TestBaggage(t *testing.T) {
|
||||
|
||||
require.Equal(t, expected, got)
|
||||
}
|
||||
|
||||
func TestResourceTarget_ChatTitleNotLeaked(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
chat := database.Chat{
|
||||
ID: uuid.UUID{1},
|
||||
Title: "sensitive-project-name",
|
||||
}
|
||||
target := audit.ResourceTarget(chat)
|
||||
require.NotContains(t, target, chat.Title,
|
||||
"ResourceTarget for Chat must not contain the title; it should use a UUID prefix")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user