mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
fix(runner): a secure field's value does not reach state.lastAction either
folio extracts lastAction, and extractor values are persisted as extractor_changes, so the password still reached the run directory through the spec after the three render sites were closed. The wrap sits in the runner rather than in lastActionFields because the hosts hold the next step's tree, not the one the action was chosen against: a field that stops being secure between the two would publish what the trace withheld. Live and replay now agree byte for byte.
This commit is contained in:
1 parent
38d328df90
commit
66fd5bce5d
7 files changed
+181
-8
No files matched your search
@@ -134,6 +134,11 @@ export interface ExceptionRecord {
|
||||
* reported", which is weaker than "the app never restarted": a target whose
|
||||
* foreground the runner cannot read never relaunches the app and cannot promise
|
||||
* that either.
|
||||
*
|
||||
* `text` is the value as the record renders it: `[redacted]` wherever the
|
||||
* target may be a credential entry, which on Android is every target, since it
|
||||
* reports nothing either way. Read the field off `ax` to reason about what it
|
||||
* holds.
|
||||
*/
|
||||
export type LastAction = Action & { applied: true | null; relaunched: true | null };
|
||||
|
||||
|
||||
Reference in new issue
Block a user