mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-05-13 03:52:00 +00:00
Flip the default for HERMES_REDACT_SECRETS from off to on so the redactor already wired into send_message_tool, logs, and tool output actually runs on a fresh install. - agent/redact.py: env-var default "" → "true" - hermes_cli/config.py: DEFAULT_CONFIG security.redact_secrets True; two config-template comments rewritten - gateway/run.py + cli.py: startup log / banner warning when the user has explicitly opted out, so the downgrade is visible in agent.log and at CLI banner time - docs/reference/environment-variables.md: description reconciled - tests: flipped the default-pin, restructured the force=True regression test to explicit-false instead of unset Users who need raw credential values (redactor development) can still opt out via security.redact_secrets: false in config.yaml or HERMES_REDACT_SECRETS=false in .env. Closes #17691. Addresses #20785 (short-term output-pipeline recommendation).
This commit is contained in:
parent
d856f4535d
commit
fb1ce793e6
7 changed files with 81 additions and 28 deletions
|
|
@ -2860,6 +2860,29 @@ class GatewayRunner:
|
|||
)
|
||||
except Exception:
|
||||
pass
|
||||
# Redaction status: ON by default (#17691). Surface a prominent
|
||||
# warning if an operator has explicitly opted out so they don't
|
||||
# forget the downgrade is active — the redactor snapshots its
|
||||
# state at import time, so this log line is the source of truth
|
||||
# for this process's lifetime.
|
||||
try:
|
||||
_redact_raw = os.getenv("HERMES_REDACT_SECRETS", "true")
|
||||
_redact_on = _redact_raw.lower() in ("1", "true", "yes", "on")
|
||||
if _redact_on:
|
||||
logger.info(
|
||||
"Secret redaction: ENABLED (tool output, logs, and chat "
|
||||
"responses are scrubbed before delivery)"
|
||||
)
|
||||
else:
|
||||
logger.warning(
|
||||
"Secret redaction: DISABLED (HERMES_REDACT_SECRETS=%s). "
|
||||
"API keys and tokens may appear verbatim in chat output, "
|
||||
"session JSONs, and logs. Set security.redact_secrets: true "
|
||||
"in config.yaml to re-enable.",
|
||||
_redact_raw,
|
||||
)
|
||||
except Exception:
|
||||
pass
|
||||
try:
|
||||
from hermes_cli.profiles import get_active_profile_name
|
||||
_profile = get_active_profile_name()
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue