mirror of
https://github.com/QwenLM/qwen-code.git
synced 2026-07-30 11:24:36 +00:00
* feat(external-context): add submitted-prompt auto recall Add an opt-in Hook-only profile that derives bounded retrieval queries from submitted prompt provenance while preserving the existing on-demand MCP contract. Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com> * fix(external-context): harden auto recall query sanitization (#7877) Address review feedback on the submitted-prompt auto recall Hook: - Bound the sanitizer input before the redaction regexes run so a worst-case prompt cannot drive the assignment regex into quadratic backtracking that blocks the event loop past the wall-clock budget. - Test the whole assignment for secret names so a leading label such as "Deploy failed:" can no longer claim the match and leak an api_key=. - Skip the interactive E2E under container sandboxes (docker/podman), matching the cron-interactive precedent. - Restore real undici coverage for a malformed proxy environment value. - Make the wall-clock-budget test exercise the internal timer rather than the provider timeout, and give the backtracking regression test a shape that actually backtracks. - Clarify that the v2 top-level timeoutMs applies only to the on-demand MCP path, and note session-lifetime context accumulation in the design doc. * fix(external-context): complete secret redaction, guard MCP config version (#7877) Anchor the secret keyword to the name that owns the separator so a leading prose label can no longer claim the match. This redacts spaced separators (api_key = sk-...) and inline JSON ({"api_key": "..."}), and stops over-redacting ordinary prose such as "readme: token refresh flow". Also reject non-version-1 configs in runMcp with a clear startup error so an auto-recall (v2) config cannot silently expose a second retrieval surface. --------- Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com> Co-authored-by: Qwen Code Autofix <qwen-code-autofix@users.noreply.github.com> Co-authored-by: qwen-code-dev-bot <qwen-code-dev@service.alibaba.com> |
||
|---|---|---|
| .. | ||
| external-context | ||