Skip to content

Strip sensitive information from serialized chat history #226

Description

@mattprintz

Background:

As part of issue #215, we will be saving chat history to the notebook.
As part of issues #211 & #212 we will be codifying how users can add/define secrets that should not be shared.
Beakerhub already has a concept of secrets at the deployment level.

Issue:

As the chat history may contain code, environment variables, etc, it is possible for sensitive information such as API key, auth tokens, etc to be included in the chat history. This could result in leakage of the sensitive data when publishing or sharing a beaker notebook.

Potential solutions:

  • on_save trigger that goes through content of file and replaces/removes sensitive strings if exact matches are found
  • Instead of stripping sensitive strings, we could potentially encrypt the chat history so that it can only be loaded by the same user
    • This would likely piggy-back off of jupyter's "trusted notebook" system and notebook signing.

Notes:

  • There is no such strip feature built into Jupyter, so we may want to sanitize the full notebook, including code blocks and outputs in case sensitive values are put there as well.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions