Files
echo-core/.gitignore
Marius Mutu a62e4d4ab7 fix(gitignore): tipare de secrete, ca auto-commit-ul să nu mai publice credențiale
Dashboard-ul face `git add -A` + commit + push fără intervenție umană
(dashboard/handlers/git.py:110). Regulile pe nume exact acopereau doar fișierele
observate, nu clasele lor: `bridge/whatsapp/auth/` era ignorat, dar
`auth.bak-*/` nu — așa a ajuns creds.json cu chei de sesiune WhatsApp pe Gitea.

Audit: din 21 de nume plauzibile testate (.env.local, credentials.json, token.json,
id_rsa, auth-old/, server.pem, cookies.txt, dump.sql, config.json.bak, nohup.out),
toate 21 treceau nestingherite. Acum toate sunt prinse.

- bridge/whatsapp/auth*/ acoperă orice variantă de director de stare Baileys
- .env* (cu excepție pentru .env.example), *.pem, *.key, id_rsa*, id_ed25519*
- *token*.json, *credential*.json, client_secret*.json, creds.json, cookies*.txt
- backup-uri/dump-uri: *.bak, *.backup, *.orig, *.dump, *.sql, *.tar.gz, *.zip,
  *.bundle — cu !memory/kb/**/*.bak pentru notițele legitime din KB
- nohup.out, core.[0-9]*

Verificat în ambele direcții: `git ls-files | git check-ignore --stdin` nu
întoarce nimic (niciun fișier tracked nu devine ignorat), iar cele 21 de nume
ipotetice sunt acum toate ignorate.

Restul auditului e curat: zero secrete în fișierele tracked, config.json fără
credențiale (keyring folosit corect), credentials/, dashboard/.env,
memory/echo.sqlite și bridge/whatsapp/auth/ deja acoperite.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0188YmDTUAzVvZDVh8JL8xSa
2026-08-31 22:04:58 +00:00

82 lines
1.6 KiB
Plaintext

.venv/
.venv-pockettts/
venv/
__pycache__/
*.pyc
*.pyo
*.egg-info/
sessions/
logs/
memory/*
!memory/kb/
memory/kb/*.sqlite
*.sqlite
.env
*.secret
.DS_Store
*.swp
bridge/whatsapp/node_modules/
bridge/whatsapp/auth/
.vscode/
.idea/
credentials/
.claude/
*.pid
memory.bak/
.use_openrouter
.gstack/
# jsonlock sidecar files (src/jsonlock.py) — empty flock handles, never data
*.lock
# Runtime state — auto-modified by dashboard/cron/heartbeat
approved-tasks.json
dashboard/status.json
tools/anaf-monitor/monitor.log
models/
# ── Secrete: TIPARE, nu nume exacte ─────────────────────────────
# Dashboard-ul face `git add -A` (dashboard/handlers/git.py), deci orice fișier
# neignorat ajunge automat comis și împins. Regulile pe nume exact au lăsat să
# treacă bridge/whatsapp/auth.bak-*/ cu creds.json — chei de sesiune WhatsApp
# publicate pe Gitea din 2026-08-22 până la curățarea din 2026-08-31.
# Orice regulă nouă de secret se scrie ca tipar, ca varianta de nume să nu scape.
# Stare Baileys sub orice nume (auth/, auth.bak-*/, auth-old/, auth_backup/)
bridge/whatsapp/auth*/
# Variante de .env (.env.local, .env.bak, dashboard/.env.backup)
.env*
!.env.example
# Chei și certificate
*.pem
*.key
*.p12
*.pfx
id_rsa*
id_ed25519*
# Fișiere de credențiale
*token*.json
*credential*.json
client_secret*.json
creds.json
cookies*.txt
# Backup-uri și dump-uri (pot conține orice din cele de mai sus)
*.bak
*.backup
*.orig
*.dump
*.sql
*.tar.gz
*.tgz
*.zip
*.bundle
!memory/kb/**/*.bak
# Gunoi de runtime
nohup.out
core.[0-9]*