mirror of
https://github.com/headroomlabs-ai/headroom.git
synced 2026-08-10 14:27:00 -04:00
## Description Extracts the pure image-base64 request-log redaction decision/transform logic from `request_logger.py` into a dedicated policy module. `RequestLogger` remains the owner of the Prometheus-facing redaction counter and existing request_logger constants remain available for compatibility. Closes # ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Documentation update - [ ] Performance improvement - [x] Code refactoring (no functional changes) ## Changes Made - Added `headroom.proxy.request_log_redaction_policy` with a pure `RedactionResult` outcome. - Kept global redaction metrics/counter side effects in `request_logger.py`. - Added direct policy tests for count reporting, nested image paths, and data URL threshold behavior. - Carried forward the LiteLLM callback compatibility shim needed for current mypy on `main`. ## Testing - [x] Unit tests pass (`pytest`) - [x] Linting passes (`ruff check .`) - [x] Type checking passes (`mypy headroom`) - [x] New tests added for new functionality - [ ] Manual testing performed ### Test Output ```text python -m pytest tests\test_request_log_redaction_policy.py tests\test_image_log_redaction.py 20 passed in 0.31s python -m ruff check . All checks passed! python -m ruff format --check . 1095 files already formatted python -m mypy headroom --ignore-missing-imports Success: no issues found in 409 source files gitleaks protect --staged --no-banner --redact no leaks found ``` ## Real Behavior Proof - Environment: Windows, Python 3.13.13, branch `jd/architecture-slice-23`. - Exact command / steps: ran targeted request-log redaction tests, ruff, ruff format check, mypy, and staged gitleaks scan. - Observed result: redaction behavior remains covered through existing logger tests and new pure policy tests; local lint/type/security checks pass. - Not tested: full proxy runtime; this slice only moves pure redaction policy and keeps the logger entry point intact. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Screenshots (if applicable) N/A ## Additional Notes Documentation and changelog updates are N/A for this internal architecture-only refactor. The push reported existing default-branch Dependabot alerts; no staged secret leaks were found for this PR.
51 lines
1.7 KiB
Python
51 lines
1.7 KiB
Python
from __future__ import annotations
|
|
|
|
from headroom.proxy.request_log_redaction_policy import (
|
|
IMAGE_BASE64_REDACT_THRESHOLD_BYTES,
|
|
IMAGE_BASE64_REPLACEMENT_TEMPLATE,
|
|
is_base64_image_payload,
|
|
redact_image_base64_value,
|
|
)
|
|
|
|
|
|
def test_policy_reports_redaction_count_without_side_effects() -> None:
|
|
image_payload = "x" * IMAGE_BASE64_REDACT_THRESHOLD_BYTES
|
|
non_image_payload = "y" * IMAGE_BASE64_REDACT_THRESHOLD_BYTES
|
|
|
|
result = redact_image_base64_value(
|
|
{
|
|
"source": {"data": image_payload},
|
|
"signature": non_image_payload,
|
|
}
|
|
)
|
|
|
|
assert result.redactions == 1
|
|
assert result.value["source"]["data"] == IMAGE_BASE64_REPLACEMENT_TEMPLATE.format(
|
|
n=len(image_payload)
|
|
)
|
|
assert result.value["signature"] == non_image_payload
|
|
|
|
|
|
def test_policy_counts_nested_list_redactions() -> None:
|
|
data_url = "data:image/png;base64," + ("A" * IMAGE_BASE64_REDACT_THRESHOLD_BYTES)
|
|
direct_payload = "B" * IMAGE_BASE64_REDACT_THRESHOLD_BYTES
|
|
|
|
result = redact_image_base64_value(
|
|
[{"content": [{"image_url": {"url": data_url}}, {"image": direct_payload}]}]
|
|
)
|
|
|
|
assert result.redactions == 2
|
|
assert result.value[0]["content"][0]["image_url"]["url"] == (
|
|
IMAGE_BASE64_REPLACEMENT_TEMPLATE.format(n=len(data_url))
|
|
)
|
|
assert result.value[0]["content"][1]["image"] == IMAGE_BASE64_REPLACEMENT_TEMPLATE.format(
|
|
n=len(direct_payload)
|
|
)
|
|
|
|
|
|
def test_explicit_image_data_url_requires_threshold() -> None:
|
|
short_data_url = "data:image/png;base64,abc"
|
|
long_data_url = "data:image/png;base64," + ("A" * IMAGE_BASE64_REDACT_THRESHOLD_BYTES)
|
|
|
|
assert not is_base64_image_payload(short_data_url)
|
|
assert is_base64_image_payload(long_data_url)
|