Sitelet https://github.com/NodeOps-app/createos-python-sdk/commit/560fd7a9a0fff625979626cd4b41d0d93acb6baa
Skip to content

Commit 560fd7a

Browse files
fix(security): redact delegated token in formatted output (#4)
1 parent 52d567c commit 560fd7a

3 files changed

Lines changed: 8 additions & 1 deletion

File tree

‎CHANGELOG.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,11 @@ Versions follow [Semantic Versioning](https://semver.org/).
1717

1818
## [Unreleased]
1919

20+
### Fixed
21+
22+
- Redact plaintext sandbox access tokens from response representations to
23+
prevent accidental disclosure in logs.
24+
2025
### Changed
2126

2227
- Set the next package version to `0.1.3` on the patch release line.

‎src/createos/models.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -592,7 +592,7 @@ class Sandbox(Model):
592592
class SandboxAccessTokenCreateResponse(Model):
593593
"""Plaintext delegated token returned only on creation or rotation."""
594594

595-
token: str
595+
token: str = field(repr=False)
596596
enabled: bool
597597
created_at: datetime
598598
rotated_at: datetime | None = None

‎tests/test_sdk.py‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -82,6 +82,8 @@ def handler(request):
8282
sandbox = client.get_sandbox("sb-1")
8383
created = sandbox.create_access_token()
8484
assert created.token == "skp_sb_first" and created.created_at.year == 2026
85+
assert created.token not in repr(created)
86+
assert "enabled=True" in repr(created)
8587
assert sandbox.get_access_token().token_hint == "skp_sb...irst"
8688
worker = sandbox.with_access_token(created.token)
8789
assert worker is not sandbox and worker.files is not sandbox.files

0 commit comments

Comments
 (0)