Skip to content

Extract wire debug redaction policy - #1972

Merged
JerrettDavis merged 3 commits into
mainfrom
jd/architecture-slice-25
Jul 12, 2026
Merged

Extract wire debug redaction policy#1972
JerrettDavis merged 3 commits into
mainfrom
jd/architecture-slice-25

Conversation

@JerrettDavis

Copy link
Copy Markdown
Collaborator

Description

Extracts the pure secret-redaction logic used by opt-in Codex wire-debug capture from helpers.py into headroom.proxy.wire_debug_redaction_policy. This keeps the debug capture path behavior intact while making the sensitive-key policy directly testable.

Closes #

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Performance improvement
  • Code refactoring (no functional changes)

Changes Made

  • Added wire_debug_redaction_policy.py for secret-key matching and recursive wire-debug redaction.
  • Kept existing helper entry points and private compatibility names delegating to the extracted policy.
  • Added direct tests for direct secret headers, nested suffix-matched secrets, and key normalization.
  • Carried forward the LiteLLM callback compatibility shim needed for current mypy on main.

Testing

  • Unit tests pass (pytest)
  • Linting passes (ruff check .)
  • Type checking passes (mypy headroom)
  • New tests added for new functionality
  • Manual testing performed

Test Output

python -m pytest tests\test_wire_debug_redaction_policy.py
3 passed in 0.16s

python -m ruff check .
All checks passed!

python -m ruff format --check .
1095 files already formatted

python -m mypy headroom --ignore-missing-imports
Success: no issues found in 409 source files

gitleaks protect --staged --no-banner --redact
no leaks found

Real Behavior Proof

  • Environment: Windows, Python 3.13.13, branch jd/architecture-slice-25.
  • Exact command / steps: ran focused wire-debug redaction tests, ruff, ruff format check, mypy, and staged gitleaks scan.
  • Observed result: redaction policy is directly covered and local lint/type/security checks pass.
  • Not tested: full proxy wire-debug capture runtime; this slice preserves the existing helper entry points.

Review Readiness

  • I have performed a self-review
  • This PR is ready for human review

Checklist

  • My code follows the project's style guidelines
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • I have updated the CHANGELOG.md if applicable

Screenshots (if applicable)

N/A

Additional Notes

Documentation and changelog updates are N/A for this internal architecture-only refactor. The push reported existing default-branch Dependabot alerts; no staged secret leaks were found for this PR.

@github-actions

Copy link
Copy Markdown
Contributor

PR governance

This PR follows the template and is marked ready for human review.

@github-actions github-actions Bot added the status: ready for review Pull request body is complete and the author marked it ready for human review label Jul 10, 2026
@JerrettDavis
JerrettDavis force-pushed the jd/architecture-slice-25 branch from 0254fdc to 71d5e5b Compare July 11, 2026 00:12
@JerrettDavis
JerrettDavis merged commit 4640587 into main Jul 12, 2026
28 checks passed
@JerrettDavis
JerrettDavis deleted the jd/architecture-slice-25 branch July 12, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: ready for review Pull request body is complete and the author marked it ready for human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant