mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-04 12:07:09 +00:00
fix(verifier): a secure field's typed value never reaches the record
A folio login run wrote the account email and password in cleartext into llm-calls.jsonl, 166 times in one run, beside screenshots of the same screens. Three sites rendered it: the recent-action memory, the candidate list, and the trace. One helper now covers all three so a fourth cannot bypass it, and the driver still receives the real text. Android redacts every typed value because it cannot tell a secure field from any other. That asymmetry is deliberate and documented: safe by default on the target that cannot tell.
This commit is contained in:
1 parent
b1e95739ad
commit
38d328df90
12 files changed
+418
-16
No files matched your search
@@ -124,6 +124,14 @@ func nodeObject(runtime *goja.Runtime, tree *hierarchy.Tree, node *hierarchy.Nod
|
||||
_ = object.Set("focused", element.Focused)
|
||||
_ = object.Set("selected", element.Selected)
|
||||
_ = object.Set("editable", element.Editable)
|
||||
// Three-valued, unlike the other state flags: null where the platform
|
||||
// reported nothing at all, which is what separates an ordinary field from a
|
||||
// password field on a platform that cannot tell them apart.
|
||||
var secure any
|
||||
if element.SecureReported() {
|
||||
secure = element.Secure
|
||||
}
|
||||
_ = object.Set("secure", secure)
|
||||
_ = object.Set("x", centerX)
|
||||
_ = object.Set("y", centerY)
|
||||
_ = object.Set(tagSelector, unambiguousSelector(tree, node, selector))
|
||||
|
||||
Reference in new issue
Block a user