mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-03 03:27:10 +00:00
fix(verifier): a secure field's typed value never reaches the record
A folio login run wrote the account email and password in cleartext into llm-calls.jsonl, 166 times in one run, beside screenshots of the same screens. Three sites rendered it: the recent-action memory, the candidate list, and the trace. One helper now covers all three so a fourth cannot bypass it, and the driver still receives the real text. Android redacts every typed value because it cannot tell a secure field from any other. That asymmetry is deliberate and documented: safe by default on the target that cannot tell.
This commit is contained in:
1 parent
b1e95739ad
commit
38d328df90
12 files changed
+418
-16
No files matched your search
@@ -75,11 +75,11 @@ func TestDescribeActionNamesGesturesByOrigin(t *testing.T) {
|
||||
Kind: verifier.ActionKindScroll, Direction: "down",
|
||||
FromX: 200, FromY: 500, ToX: 200, ToY: 340,
|
||||
}
|
||||
if got := describeAction(builtin); got != "Scroll down (200,500)" {
|
||||
if got := describeAction(builtin, nil); got != "Scroll down (200,500)" {
|
||||
t.Errorf("builtin gesture described as %q, want the drag origin", got)
|
||||
}
|
||||
authored := verifier.Action{Kind: verifier.ActionKindScroll, Direction: "up", On: "id:List"}
|
||||
if got := describeAction(authored); got != "Scroll up id:List" {
|
||||
if got := describeAction(authored, nil); got != "Scroll up id:List" {
|
||||
t.Errorf("authored scroll described as %q, want its selector", got)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user