From 4ae34f8dc33b5a7fdcae7110f46fef463bd4c497 Mon Sep 17 00:00:00 2001 From: 0PeterAdel <1peteradel@gmail.com> Date: Wed, 8 Jul 2026 12:15:54 +0300 Subject: [PATCH 1/3] security: mask code completion API keys in logs --- main.go | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/main.go b/main.go index 97d60e0..fb7412d 100644 --- a/main.go +++ b/main.go @@ -551,8 +551,15 @@ func getRandomApiKey(paramStr string) string { rand.Seed(time.Now().UnixNano()) randomIndex := rand.Intn(len(params)) fmt.Println("Code completion API Key index:", randomIndex) - fmt.Println("Code completion API Key:", strings.TrimSpace(params[randomIndex])) - return strings.TrimSpace(params[randomIndex]) + key := strings.TrimSpace(params[randomIndex]) + maskedKey := key + if len(key) > 12 { + maskedKey = key[:4] + "..." + key[len(key)-4:] + } else if len(key) > 0 { + maskedKey = "******" + } + fmt.Println("Code completion API Key:", maskedKey) + return key } func ConstructRequestBody(body []byte, cfg *config) []byte { From 9171156fd91540e628e88d86f286865dec3b8db3 Mon Sep 17 00:00:00 2001 From: Peter Rafat Adel <148042680+0PeterAdel@users.noreply.github.com> Date: Fri, 28 Aug 2026 05:44:36 +0300 Subject: [PATCH 2/3] security: stop logging API key material --- main.go | 7 ----- main_test.go | 74 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 74 insertions(+), 7 deletions(-) create mode 100644 main_test.go diff --git a/main.go b/main.go index fb7412d..af71f10 100644 --- a/main.go +++ b/main.go @@ -552,13 +552,6 @@ func getRandomApiKey(paramStr string) string { randomIndex := rand.Intn(len(params)) fmt.Println("Code completion API Key index:", randomIndex) key := strings.TrimSpace(params[randomIndex]) - maskedKey := key - if len(key) > 12 { - maskedKey = key[:4] + "..." + key[len(key)-4:] - } else if len(key) > 0 { - maskedKey = "******" - } - fmt.Println("Code completion API Key:", maskedKey) return key } diff --git a/main_test.go b/main_test.go new file mode 100644 index 0000000..d74151f --- /dev/null +++ b/main_test.go @@ -0,0 +1,74 @@ +package main + +import ( + "io" + "os" + "strings" + "testing" +) + +func captureStdout(t *testing.T, fn func()) string { + t.Helper() + + originalStdout := os.Stdout + reader, writer, err := os.Pipe() + if err != nil { + t.Fatalf("create stdout pipe: %v", err) + } + + os.Stdout = writer + fn() + + if err := writer.Close(); err != nil { + t.Fatalf("close stdout writer: %v", err) + } + os.Stdout = originalStdout + + output, err := io.ReadAll(reader) + if err != nil { + t.Fatalf("read captured stdout: %v", err) + } + if err := reader.Close(); err != nil { + t.Fatalf("close stdout reader: %v", err) + } + + return string(output) +} + +func TestGetRandomApiKeyDoesNotLogKeyMaterial(t *testing.T) { + testCases := []struct { + name string + key string + }{ + {name: "long key", key: "sk-super-secret-completion-key-1234567890"}, + {name: "short key", key: "short-key"}, + } + + for _, testCase := range testCases { + t.Run(testCase.name, func(t *testing.T) { + var selectedKey string + output := captureStdout(t, func() { + selectedKey = getRandomApiKey(testCase.key) + }) + + if selectedKey != testCase.key { + t.Fatalf("selected key = %q, want %q", selectedKey, testCase.key) + } + + fragments := []string{ + testCase.key, + testCase.key[:4], + testCase.key[len(testCase.key)-4:], + } + for _, fragment := range fragments { + if strings.Contains(output, fragment) { + t.Errorf("stdout leaked API key material %q: %q", fragment, output) + } + } + + if !strings.Contains(output, "Code completion API Key index:") { + t.Errorf("stdout did not include the selected key index: %q", output) + } + }) + } +} From f30086321e5af388da3ace7d6af52aaa2ec25aa7 Mon Sep 17 00:00:00 2001 From: Peter Rafat Adel <148042680+0PeterAdel@users.noreply.github.com> Date: Wed, 30 Sep 2026 22:13:12 +0300 Subject: [PATCH 3/3] ci: request a fresh workflow run after approval expiry