feat(observability): allowlist phase-label names to prevent path/secret leakage in TUI
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 76/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- cli, observability
Research direction
Start in packages/opencode/src/session/status.ts at SessionStatus.publishPhase and inspect how warnings are logged. Review packages/tui/src/util/phase-label.ts and the existing unit-test conventions, then add coverage for an unregistered name. Done means unknown names warn and are dropped while registered phase labels continue to work.
Written by the indexing model from the issue text.
Description
Deferred from the v0.9.3 pre-release review.
Current behavior
SessionStatus.publishPhase(name, ...) in packages/opencode/src/session/status.ts accepts any string for the name argument. Today the set produced by bootstrap.* spans is static and benign, and the TUI's packages/tui/src/util/phase-label.ts falls back to "Thinking..." on unknown names.
Gap
There is no validation at the publishPhase call site that the name is limited to a registered set. A future span whose name accidentally embeds a filesystem path, a secret, or a sensitive env reference would surface as a user-visible TUI label without any signal that it was unintended.
Proposal
Add a Set<string> of known phase names. publishPhase logs a warning (not throws) when an unregistered name is used and drops the label. Cover with a unit test that asserts a warning fires on an unregistered name so a regression is loud.
Why deferred
Guardrail against a future regression; the current phase-name set is static and benign so there is no user-visible risk today.
- Dominant language
- TypeScript
- Stars
- 813
- Forks
- 134
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 62
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AltimateAI/altimate-code
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
AltimateAI/altimate-code#1323 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
AltimateAI/altimate-code#1288 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
AltimateAI/altimate-code#1285 ·
-
privacy: Altimate Base consent dialog no longer discloses persistent per-installation identifier Open
Difficulty 1/5 Under an hour Newbie friendliness 88/100
AltimateAI/altimate-code#1284 ·
-
Difficulty 2/5 Under an hour Newbie friendliness 72/100
AltimateAI/altimate-code#1283 ·
All issues in AltimateAI/altimate-code
Similar issues
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 91/100
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficulty 1/5 Under an hour Newbie friendliness 95/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100