workspace: memory content mirrored to cloud is unfiltered — no secret/PII redaction
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
跟踪 memory-write.ts、memory-extract.ts 和 memory-sync.ts 中的内存写入与镜像路径,尤其要关注 push() 将 block.content 转发给 MemoryApi.add/update 的过程。查看 workspace.tsx 和 link.ts 中与同意相关的更改,以了解上下文。完成此项工作需要达成一致的内容扫描和编辑设计,以便在启用镜像时阻止机密信息和 PII 离开本机。
由索引模型根据 Issue 内容生成。
描述
Found during v0.9.7 release review (Chaos Gremlin/Privacy Auditor persona).
memory-extract.ts's tool description explicitly invites the agent to capture 'warehouse configs found via /discover, query patterns from sql_optimize, naming conventions observed' into memory blocks. Nothing in the write path (memory-write.ts, memory-extract.ts) or the mirror path (memory-sync.ts's push() forwards block.content verbatim to MemoryApi.add/update) does secret-scanning, PII filtering, or redaction before content leaves the machine (when workspace mirroring is enabled).
Compounds the disclosure gap fixed in v0.9.7 (see bind-time consent line added in workspace.tsx/link.ts): once a user knows memory syncs and accepts that, there's still no guardrail preventing a warehouse connection string or customer-identifying value from being captured into a block and mirrored.
Deferred because this needs a content-scanning/redaction design (not a quick patch), and the feature remains gated behind the off-by-default ALTIMATE_WORKSPACE pilot flag.
- 主要语言
- TypeScript
- 星标
- 813
- 派生
- 134
- 平均合并
- 2 天 2 小时
- 30 天内合并 PR
- 67
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
AltimateAI/altimate-code 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 70/100
AltimateAI/altimate-code#1359 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
AltimateAI/altimate-code#1323 ·
-
难度 2/5 1-3 小时 新手友好度 86/100
AltimateAI/altimate-code#1288 ·
-
难度 1/5 1 小时以内 新手友好度 92/100
AltimateAI/altimate-code#1285 ·
-
privacy: Altimate Base consent dialog no longer discloses persistent per-installation identifier 未关闭
难度 1/5 1 小时以内 新手友好度 88/100
AltimateAI/altimate-code#1284 ·
查看 AltimateAI/altimate-code 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
bcgov/bc-wallet-mobile#4761 · 1 条评论 ·
-
external-issue to-triage
难度 2/5 1-3 小时 新手友好度 88/100
-
area-deployment area-integrations triage:bot-seen
难度 2/5 半天 新手友好度 86/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
refactor
难度 2/5 1-3 小时 新手友好度 84/100