Skip to content

Context Guard 0.1.3

Choose a tag to compare

@dividehex dividehex released this 12 Sep 19:04
· 12 commits to main since this release
v0.1.3
68843cd

Patch release from a code review for bugs and security issues. Scoring changes in one place: known-value drift is narrower (fewer false positives). The API and the Open WebUI filter's behaviour are otherwise unchanged; the filter file is updated (version 0.1.3), reinstall it to pick up the URL-encoding fix.

Changes since 0.1.2

Security and privacy

  • Anomaly details are redacted before they are stored, served or logged: NAME=value with a secret-looking name and common API-key, GitHub, Slack, AWS, Google, JWT and bearer-token shapes become [redacted]. The README already promised this; nothing implemented it, so a drift on a pasted key quoted the key in the log and the API.
  • ENV=value pairs whose name looks like a key, token or password are never learned as facts, so an assistant showing OPENAI_API_KEY=your-key-here is no longer scored as drift.
  • The Open WebUI filter percent-encodes the chat and message ids it puts in URLs.

Correctness

  • Known-value drift only fires for attribute kinds (IP, port, env var, version, setting). A different path, URL, hostname or container name is a different thing, not a contradiction; near-duplicates of those remain the suspicious-identifier signal's job. Previously one ordinary reply mentioning a second path could cost 15 points per new path, URL or host.
  • Background tasks (title, tags, follow-ups) no longer relabel a conversation's model when Open WebUI runs them on a different model.
  • CONTEXT_GUARD_RETENTION_DAYS=0 is rejected at startup; it used to purge every conversation, active ones included, every hour.
  • The SQLite path is opened verbatim, so paths with ?, #, % or spaces work.
  • The retention cutoff uses the same timestamp format as stored rows.
  • A request_tags field that is null or not a list is ignored instead of dropping the payload.
  • On SIGTERM the ingest worker drains the batches it holds (up to five seconds) so a turn is not cut off between writes.

Dependencies and CI

  • prometheus is built without its unused protobuf feature, removing protobuf 2.x (RUSTSEC-2024-0437) from the build.
  • CI runs cargo audit. RUSTSEC-2023-0071 (rsa) is ignored in .cargo/audit.toml with the reasoning: the crate is in the lockfile through sqlx's optional MySQL driver and is never compiled here.

Install

See the README quick install. Verified against LiteLLM v1.94.1 and Open WebUI v0.11.3.

git clone https://github.com/dividehex/context-guard
docker compose up -d --build context-guard

🤖 Generated with Claude Code

https://claude.ai/code/session_011EwPexDswd2AMNtqs8wg1Y