Dashboard-ul face `git add -A` + commit + push fără intervenție umană (dashboard/handlers/git.py:110). Regulile pe nume exact acopereau doar fișierele observate, nu clasele lor: `bridge/whatsapp/auth/` era ignorat, dar `auth.bak-*/` nu — așa a ajuns creds.json cu chei de sesiune WhatsApp pe Gitea. Audit: din 21 de nume plauzibile testate (.env.local, credentials.json, token.json, id_rsa, auth-old/, server.pem, cookies.txt, dump.sql, config.json.bak, nohup.out), toate 21 treceau nestingherite. Acum toate sunt prinse. - bridge/whatsapp/auth*/ acoperă orice variantă de director de stare Baileys - .env* (cu excepție pentru .env.example), *.pem, *.key, id_rsa*, id_ed25519* - *token*.json, *credential*.json, client_secret*.json, creds.json, cookies*.txt - backup-uri/dump-uri: *.bak, *.backup, *.orig, *.dump, *.sql, *.tar.gz, *.zip, *.bundle — cu !memory/kb/**/*.bak pentru notițele legitime din KB - nohup.out, core.[0-9]* Verificat în ambele direcții: `git ls-files | git check-ignore --stdin` nu întoarce nimic (niciun fișier tracked nu devine ignorat), iar cele 21 de nume ipotetice sunt acum toate ignorate. Restul auditului e curat: zero secrete în fișierele tracked, config.json fără credențiale (keyring folosit corect), credentials/, dashboard/.env, memory/echo.sqlite și bridge/whatsapp/auth/ deja acoperite. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0188YmDTUAzVvZDVh8JL8xSa
82 lines
1.6 KiB
Plaintext
82 lines
1.6 KiB
Plaintext
.venv/
|
|
.venv-pockettts/
|
|
venv/
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
*.egg-info/
|
|
sessions/
|
|
logs/
|
|
memory/*
|
|
!memory/kb/
|
|
memory/kb/*.sqlite
|
|
*.sqlite
|
|
.env
|
|
*.secret
|
|
.DS_Store
|
|
*.swp
|
|
bridge/whatsapp/node_modules/
|
|
bridge/whatsapp/auth/
|
|
.vscode/
|
|
.idea/
|
|
credentials/
|
|
.claude/
|
|
*.pid
|
|
memory.bak/
|
|
.use_openrouter
|
|
.gstack/
|
|
|
|
# jsonlock sidecar files (src/jsonlock.py) — empty flock handles, never data
|
|
*.lock
|
|
|
|
# Runtime state — auto-modified by dashboard/cron/heartbeat
|
|
approved-tasks.json
|
|
dashboard/status.json
|
|
tools/anaf-monitor/monitor.log
|
|
models/
|
|
|
|
# ── Secrete: TIPARE, nu nume exacte ─────────────────────────────
|
|
# Dashboard-ul face `git add -A` (dashboard/handlers/git.py), deci orice fișier
|
|
# neignorat ajunge automat comis și împins. Regulile pe nume exact au lăsat să
|
|
# treacă bridge/whatsapp/auth.bak-*/ cu creds.json — chei de sesiune WhatsApp
|
|
# publicate pe Gitea din 2026-08-22 până la curățarea din 2026-08-31.
|
|
# Orice regulă nouă de secret se scrie ca tipar, ca varianta de nume să nu scape.
|
|
|
|
# Stare Baileys sub orice nume (auth/, auth.bak-*/, auth-old/, auth_backup/)
|
|
bridge/whatsapp/auth*/
|
|
|
|
# Variante de .env (.env.local, .env.bak, dashboard/.env.backup)
|
|
.env*
|
|
!.env.example
|
|
|
|
# Chei și certificate
|
|
*.pem
|
|
*.key
|
|
*.p12
|
|
*.pfx
|
|
id_rsa*
|
|
id_ed25519*
|
|
|
|
# Fișiere de credențiale
|
|
*token*.json
|
|
*credential*.json
|
|
client_secret*.json
|
|
creds.json
|
|
cookies*.txt
|
|
|
|
# Backup-uri și dump-uri (pot conține orice din cele de mai sus)
|
|
*.bak
|
|
*.backup
|
|
*.orig
|
|
*.dump
|
|
*.sql
|
|
*.tar.gz
|
|
*.tgz
|
|
*.zip
|
|
*.bundle
|
|
!memory/kb/**/*.bak
|
|
|
|
# Gunoi de runtime
|
|
nohup.out
|
|
core.[0-9]*
|