fix(subprocess): share password scrub with direct spawners

This commit is contained in:
ZiyaZhang
2026-07-28 02:19:18 -07:00
parent 6b7b2f8010
commit d0cbf825a5
7 changed files with 47 additions and 7 deletions
@@ -5,7 +5,7 @@
*/
import { execFile, spawn } from 'node:child_process'
import { scrubbedParentEnv } from '@deepseek-ai/dsh-subprocess'
import { scrubbedParentEnv, SENSITIVE_ENV_PATTERN } from '@deepseek-ai/dsh-subprocess'
import { promisify } from 'node:util'
import type { PackageJsonFile } from '../documents/package-json-file.ts'
import { PnpmWorkspaceFile } from '../documents/pnpm-workspace-file.ts'
@@ -60,7 +60,7 @@ export async function probePackageManagerVersion(name: PackageManagerName, cwd:
*/
export function scrubEnvironment(environment?: NodeJS.ProcessEnv): NodeJS.ProcessEnv {
if (environment === undefined) return scrubbedParentEnv()
return Object.fromEntries(Object.entries(environment).filter(([name]) => !/(?:KEY|SECRET|TOKEN)/i.test(name)))
return Object.fromEntries(Object.entries(environment).filter(([name]) => !SENSITIVE_ENV_PATTERN.test(name)))
}
/** Node child-process command runner with inherited stdio and quiescent completion. */
+6 -1
View File
@@ -309,7 +309,12 @@ describe('package manager strategies', () => {
await expect(npm.install('/tmp', failed)).rejects.toThrow('exited with code 2')
const killed: CommandRunner = { run: async () => ({ exitCode: null, signal: 'SIGTERM' }) }
await expect(npm.build('/tmp', killed)).rejects.toThrow('killed by SIGTERM')
expect(scrubEnvironment({ PATH: '/bin', API_KEY: 'secret', TOKEN_VALUE: 'secret' })).toEqual({ PATH: '/bin' })
expect(scrubEnvironment({
PATH: '/bin',
API_KEY: 'secret',
DB_PASSWORD: 'secret',
TOKEN_VALUE: 'secret',
})).toEqual({ PATH: '/bin' })
})
it('probes versions and runs real child-process boundaries', async () => {