develop-hamza-1 #120

Merged
hamza.khyari merged 10 commits from develop-hamza-1 into master 2026-02-19 15:40:45 +00:00

10 Commits

Author SHA1 Message Date
hamza.khyari 708574912e Merge pull request 'feat(ops): add cleanup commands [H-24, CONC3]' (#117) from feature/m4-concurrency-cleanup into develop-hamza-1
CI / benchmark-publish (pull_request) Has been skipped
CI / lint (pull_request) Successful in 15s
CI / build (pull_request) Successful in 17s
CI / quality (pull_request) Successful in 18s
CI / security (pull_request) Successful in 30s
CI / typecheck (pull_request) Successful in 36s
CI / integration_tests (pull_request) Successful in 3m10s
CI / unit_tests (pull_request) Successful in 4m14s
CI / docker (pull_request) Successful in 39s
CI / coverage (pull_request) Successful in 10m56s
CI / benchmark-regression (pull_request) Successful in 8m26s
Reviewed-on: #117
2026-02-19 14:22:23 +00:00
khyari hamza cea3bad758 refactor(ops): address re-review findings for cleanup commands
- Use model_copy(update=...) in test helpers so Pydantic ge=
  validators are enforced during tests, not just env vars (NEW-1)
- Promote _extract_plan_id_from_sandbox to public staticmethod
  and reuse in CLI active-plan detection to eliminate duplicate
  plan-ID parsing logic (NEW-2)
- Cache _get_sandbox_dirs result for service instance lifetime
  and have CLI active-plan detection use the cached listing so
  /tmp is iterated only once per invocation (NEW-3)
2026-02-19 14:20:16 +00:00
khyari hamza f4c088bae8 fix(ops): address review findings for cleanup commands
- Add best-effort active plan detection from sandbox mtimes to
  protect running plans from cleanup (B1)
- Add ge= validators on all retention settings to prevent unsafe
  negative/zero values; checkpoint max requires ge=2 (B3, NB6)
- Handle CoW sandbox plan_id extraction (ca-cow-sandbox- prefix)
  so copy-on-write sandboxes are also protected (NB4)
- Add OSError guards in sandbox dir iteration for race safety (NB7)
- Add TODO markers and CLI notice for unimplemented session cleanup (NB1)
- Rebase onto develop-hamza-1 to incorporate SEC5 changes (B2)
2026-02-19 13:58:39 +00:00
khyari hamza bab4560dde feat(ops): add cleanup commands 2026-02-19 13:46:48 +00:00
khyari hamza bd38a00cf0 chore: WIP branch for feat(ops): add cleanup commands
Refs: H-24, CONC3.gc
Planned: Day 13
2026-02-19 13:46:48 +00:00
hamza.khyari 4eda3b6453 Merge pull request 'feat(security): add secrets masking and validation (H-21/SEC5)' (#116) from feature/m4-security-secrets into develop-hamza-1
CI / benchmark-publish (pull_request) Has been skipped
CI / lint (pull_request) Successful in 15s
CI / build (pull_request) Successful in 16s
CI / quality (pull_request) Successful in 20s
CI / typecheck (pull_request) Successful in 28s
CI / security (pull_request) Successful in 29s
CI / integration_tests (pull_request) Successful in 2m18s
CI / unit_tests (pull_request) Successful in 4m1s
CI / docker (pull_request) Successful in 1m1s
CI / coverage (pull_request) Successful in 11m12s
CI / benchmark-regression (pull_request) Successful in 8m25s
Reviewed-on: #116
2026-02-19 13:45:28 +00:00
khyari hamza eccaeafa64 docs(plan): mark SEC5 secrets management items complete 2026-02-19 12:46:56 +00:00
khyari hamza 064939185b fix(security): whitelist structlog processor method_name for vulture 2026-02-19 12:45:59 +00:00
khyari hamza d815339c52 feat(security): add secrets masking and validation (H-21/SEC5)
Implement centralized redaction utility that masks API keys, tokens,
and credentials across CLI output, structlog logs, and error messages.

- Add shared/redaction.py with pattern-based secret detection (sk-*,
  sk-ant-*, tok_*, Bearer tokens), sensitive key name detection,
  database URL masking, custom pattern registration, and thread-safe
  global show_secrets flag
- Add config/logging.py with structlog configuration integrating the
  secrets_masking_processor into the processor chain
- Add --show-secrets global CLI option to reveal secrets when needed
- Redact error details in main.py, project.py, and auto_debug.py
  error handlers before printing
- Wrap format_output() in formatting.py with automatic dict redaction
- Add show_secrets field and safe __repr__ to Settings model
- Add 43-scenario Behave feature (features/security_secrets.feature)
- Add 10 Robot Framework smoke tests (robot/security_secrets.robot)
- Add ASV benchmarks (benchmarks/security_secrets_bench.py)
- Add reference docs (docs/reference/secrets_handling.md)
2026-02-19 11:15:18 +00:00
khyari hamza 359e3c4af2 chore: WIP branch for feat(security): add secrets masking and validation
Refs: H-21, SEC5.secrets
Planned: Day 13
2026-02-19 11:14:43 +00:00