Implement sensitive input detection and testing for chat features#6987
Merged
Conversation
cakesoft-vaibhav
approved these changes
May 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces a comprehensive, testable frontend guard against leaking sensitive Bitcoin key material (BIP39 mnemonics, extended keys, WIF keys) through the Ask Keeper AI chat and GitHub issue draft submission flows. The previous inline regex is replaced with a robust utility that detects actual cryptographic data formats, not just keywords, and blocks their transmission. The detection logic is centralized, unit-tested, and applied both at chat send and draft submission time.
Sensitive Data Detection Utility:
src/utils/helpAiSensitiveData.tsexportingdetectSensitiveInputanddetectSensitiveInDraft, implementing detection for BIP39 mnemonic sequences, extended (xprv/xpub) keys, WIF keys, and keywords, with clear result types and messages. [1] [2]src/constants/bip39WordSet.ts, a staticSet<string>of all 2048 BIP39 English words for fast, dependency-free mnemonic detection. [1] [2]Detection Logic and Integration:
SENSITIVE_INPUT_PATTERNregex inHelpAiChat.tsxwith the new utility, ensuring all chat messages and draft submissions are scanned for sensitive data before transmission. [1] [2]submitDraftIssue(), blocking GitHub issue submissions containing sensitive data and showing an explanatory toast. [1] [2] [3]Requirements and Testing:
Design Decisions:
Migration and Rollback:
These changes ensure robust, testable protection against accidental leakage of sensitive Bitcoin key material through both chat and draft submission features.