Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
421 commits
Select commit Hold shift + click to select a range
78bf391
feat: Add Superset plugin support and OIDC authentication integration
zhb-y-agent Apr 10, 2026
c040b8b
feat(plugins): Add plugin localization support and refactor Superset …
zhb-y-agent Apr 10, 2026
6d6e61b
feat(plugins): Add plugin localization support and refactor Superset …
zhb-y-agent Apr 10, 2026
935b548
docs(设计文档): 添加插件i18n自包含方案
zhb-y-agent Apr 10, 2026
9028faf
docs(i18n): Update translation guide to include plugin translation in…
zhb-y-agent Apr 10, 2026
eae255d
feat(auth): Add OAuth2 alias and update authentication documentation
zhb-y-agent Apr 10, 2026
eb4ebd5
docs(oidc): 补充OIDC/OAuth2 Provider对接的详细要求
zhb-y-agent Apr 10, 2026
f4d9e40
feat(plugin): Add password visibility toggle and description text for…
zhb-y-agent Apr 10, 2026
9b7c24c
feat(auth): Support manual OIDC/OAuth2 endpoint configuration and add…
zhb-y-agent Apr 10, 2026
98c83f7
feat(身份迁移): 实现匿名用户到认证用户的身份迁移功能
zhb-y-agent Apr 10, 2026
37017cc
feat(migration): Add anonymous workspace data migration functionality
zhb-y-agent Apr 10, 2026
b3bde64
fix(AuthButton): Improve logout logic to handle missing end_session_e…
zhb-y-agent Apr 10, 2026
72e2ae5
fix(identity migration): Prevent duplicate triggering of anonymous to…
zhb-y-agent Apr 10, 2026
82e916e
feat(authentication): Improve identity migration flow and local stora…
zhb-y-agent Apr 10, 2026
a122e77
feat(workspace): Improve robustness of anonymous workspace migration …
zhb-y-agent Apr 10, 2026
7b98382
feat(login): Add support for IdP-initiated SSO flow
zhb-y-agent Apr 10, 2026
de3559a
Merge pull request #289 from microsoft/feature/plugin-architecture
zhb-ai Apr 10, 2026
5142bc2
feat(auth): Add silent token refresh functionality and enhance securi…
zhb-y-agent Apr 11, 2026
c5f2ad4
fix(bug): Fix abnormal display status when canceling import
zhb-y-agent Apr 11, 2026
e2c9532
fix(IdentityMigrationDialog): Fix issue with preserving workspace dat…
zhb-y-agent Apr 11, 2026
28a526c
docs: 添加数据源插件开发指南文档
zhb-y-agent Apr 11, 2026
eac6515
eat(tables_routes): Add export table to CSV/TSV functionality
zhb-y-agent Apr 11, 2026
ec86904
feat(credential vault): Add credential vault feature to support remem…
zhb-y-agent Apr 11, 2026
67b31ff
Merge pull request #290 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
a4782b1
feat(security): 新增 ConfinedDir 路径安全原语及修复漏洞
zhb-y-agent Apr 11, 2026
0768156
feat(security): Add error message sanitization and unified error resp…
zhb-y-agent Apr 11, 2026
5374ef5
Merge pull request #291 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
ef48ebb
fix: Improve error handling logic to provide more user-friendly error…
zhb-y-agent Apr 11, 2026
3ee96c5
Merge pull request #292 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
4f65c4f
fix(security): Improve error message handling to enhance security
zhb-y-agent Apr 11, 2026
e9ae67f
Merge pull request #293 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
da60eeb
fix(security): Unify error message handling to prevent sensitive info…
zhb-y-agent Apr 11, 2026
c1f9378
Merge pull request #294 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
0cb48cc
feat(security): Add LLM error classification functionality and update…
zhb-y-agent Apr 11, 2026
4cb08c6
Merge pull request #295 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
20b9f40
docs: Add and update multiple documentation files and skills
zhb-y-agent Apr 11, 2026
28088e4
Merge pull request #296 from microsoft/feature/plugin-architecture
zhb-ai Apr 11, 2026
d3a832b
data plugin ui plan
Chenglong-MS Apr 12, 2026
4dc82b6
Merge pull request #297 from microsoft/dev
zhb-ai Apr 12, 2026
e907c81
feat(auth): Improve OIDC/OAuth2 authentication flow and error handling
zhb-y-agent Apr 14, 2026
53dbe31
docs: Add configuration documentation and examples for Superset and D…
zhb-y-agent Apr 14, 2026
69166bd
Merge pull request #298 from microsoft/feature/plugin-architecture
zhb-ai Apr 14, 2026
2e10da7
halfway
Chenglong-MS Apr 14, 2026
86a6f6d
redesign data connector
Chenglong-MS Apr 15, 2026
a184067
updated data connector design
Chenglong-MS Apr 16, 2026
66ef7a0
cleanup
Chenglong-MS Apr 16, 2026
249f877
cleanup
Chenglong-MS Apr 16, 2026
0d31f4f
Merge remote-tracking branch 'origin/dev' into features/data-plugin-ui
Copilot Apr 16, 2026
4215765
Merge pull request #300 from microsoft/features/data-plugin-ui
Chenglong-MS Apr 16, 2026
87229d9
improvements
Chenglong-MS Apr 16, 2026
3023e7e
fix
Chenglong-MS Apr 16, 2026
f770ac1
add cosmosdb support
Chenglong-MS Apr 16, 2026
8ab7b03
Merge pull request #301 from microsoft/dev
zhb-ai Apr 16, 2026
01f0856
bug fix
Chenglong-MS Apr 16, 2026
fc80f38
haha
Chenglong-MS Apr 17, 2026
01b6d56
important agent redesign
Chenglong-MS Apr 17, 2026
bf1d79d
Merge branch 'dev' of https://github.com/IAMkecheng/data-formulator i…
IAMkecheng Apr 17, 2026
5ecbb5b
fix bugs and add test game dataset
IAMkecheng Apr 21, 2026
49169b7
new agent
Chenglong-MS Apr 22, 2026
f0a48a3
sidebar data load
Chenglong-MS Apr 22, 2026
ebc27e0
minor
Chenglong-MS Apr 22, 2026
b8793cc
fixes
Chenglong-MS Apr 22, 2026
50916b4
Update instantiate-spec.ts
IAMkecheng Apr 22, 2026
50323e5
Merge branch 'microsoft:dev' into dev
IAMkecheng Apr 22, 2026
460f496
Merge pull request #302 from IAMkecheng/dev
Chenglong-MS Apr 22, 2026
162cf9a
gallery fixes
Chenglong-MS Apr 22, 2026
3673fe9
gallery fix
Chenglong-MS Apr 22, 2026
22c9388
Merge pull request #305 from microsoft/dev
zhb-ai Apr 22, 2026
fadb7f0
Add SSO token support for auto-connection in DataConnector and Supers…
zhb-y-agent Apr 22, 2026
fe6da49
Enhance DataAgent action handling and retry logic
zhb-y-agent Apr 22, 2026
8f83094
Implement CSV streaming export functionality and enhance download UI
zhb-y-agent Apr 22, 2026
124ac0a
Enhance CSV export functionality with improved filename handling
zhb-y-agent Apr 22, 2026
d805588
docs(design-docs): 添加DataAgent工具调用过多问题的分析文档
zhb-y-agent Apr 22, 2026
4c5e4c7
Enhance internationalization support by implementing message_code pat…
zhb-y-agent Apr 22, 2026
f6bfbf0
Refactor workspace session management and enhance UI components
zhb-y-agent Apr 22, 2026
ed1aeec
Implement delete connector functionality in DataSourceSidebar
zhb-y-agent Apr 22, 2026
4d580a8
Enhance DataAgent and UI components with field display names support
zhb-y-agent Apr 22, 2026
de0d828
Enhance data table formatting and tooltip configuration
zhb-y-agent Apr 22, 2026
145ae4f
Refactor UUID generation for session IDs across components
zhb-ai Apr 23, 2026
6d42f05
Implement secure context check for OIDC authentication
zhb-ai Apr 23, 2026
e5fe11f
docs: 新增SSO门户一键登录和统一错误处理设计文档
zhb-y-agent Apr 23, 2026
9898136
docs(auth): 新增统一认证与凭证管理架构设计文档
zhb-y-agent Apr 23, 2026
530245d
docs: 新增统一错误处理机制和认证架构设计文档
zhb-y-agent Apr 23, 2026
a2da2f3
feat: Add Unified Error Handling System
zhb-y-agent Apr 23, 2026
7d1e9a6
feat: Implement automatic file upload conversion to parquet format an…
zhb-y-agent Apr 23, 2026
b4bc04b
refactor(data stream): Improve NDJSON data parsing and processing logic
zhb-y-agent Apr 23, 2026
483e7dd
fix: Improve error handling and logging
zhb-y-agent Apr 23, 2026
21146b6
docs(streaming-protocol): Add frontend-backend streaming communicatio…
zhb-y-agent Apr 23, 2026
5ef8425
Update data agent tool descriptions and enhance table context informa…
zhb-y-agent Apr 23, 2026
57c2188
feat(agent): Add execution code purpose description and optimize thin…
zhb-y-agent Apr 23, 2026
025175f
Merge pull request #306 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
17094ec
feat(logging): Implement log sanitization to protect sensitive data
zhb-ai Apr 24, 2026
a32b372
docs(error-handling): Update error handling skill documentation and a…
zhb-ai Apr 24, 2026
c2372b2
docs: change name
zhb-ai Apr 24, 2026
4a88355
refactor(error-handling): Enhance error handling in DataConnector and…
zhb-ai Apr 24, 2026
4d34059
add doc
zhb-ai Apr 24, 2026
29f0dc4
Merge pull request #307 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
ebc63bf
update doc
zhb-y-agent Apr 24, 2026
0a3bc67
Merge branch 'feature/plugin-architecture' of https://github.com/micr…
zhb-y-agent Apr 24, 2026
fc23f4b
docs: Update documentation and skill descriptions
zhb-y-agent Apr 24, 2026
ae00939
refactor(workspace): Change default workspace name from 'default' to …
zhb-y-agent Apr 24, 2026
1bcd07b
feat(security): Implement safety checks and deployment restrictions
zhb-y-agent Apr 24, 2026
a9bbcf7
docs: Update path security related documentation and test instructions
zhb-y-agent Apr 24, 2026
fad5065
docs: Add test-driven development workflow documentation
zhb-y-agent Apr 24, 2026
5fe5754
fix: Unify error handling protocol, all application errors return HTT…
zhb-y-agent Apr 24, 2026
0eb4149
fix(security): Enhance path security checks and modify workspace crea…
zhb-y-agent Apr 24, 2026
fa0c7ce
fix(security): Enhance security for error handling and path validation
zhb-y-agent Apr 24, 2026
100fe14
fix(tests): Update test cases to match latest implementation
zhb-y-agent Apr 24, 2026
cd9fe9d
Merge pull request #309 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
cb4578c
feat: Support backend OIDC authentication mode with TokenStore integr…
zhb-y-agent Apr 24, 2026
7204f2a
feat(data source sidebar): Add smart filters and table search functio…
zhb-y-agent Apr 24, 2026
0f26231
feat(data source): Enhance data preview and filtering functionality
zhb-y-agent Apr 24, 2026
a424860
Merge pull request #310 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
6b97b59
feat(data connector): Add column value query API to support smart fil…
zhb-y-agent Apr 24, 2026
5bd1f58
Merge pull request #311 from microsoft/feature/plugin-architecture
zhb-ai Apr 24, 2026
b31656a
refactor(auth): Refactor OIDC authentication mode auto-detection logic
zhb-y-agent Apr 25, 2026
116bf06
feat(data preview): Add connector table preview component and integra…
zhb-y-agent Apr 25, 2026
5d3a976
docs: Add server migration guide documentation
zhb-y-agent Apr 25, 2026
b55cbd9
test(conftest): Add environment isolation fixtures to prevent test po…
zhb-y-agent Apr 25, 2026
6b7c341
feat(connection management): Add disconnect functionality
zhb-y-agent Apr 25, 2026
d18bc6d
fix: Ensure user identity information fields are string type
zhb-y-agent Apr 25, 2026
e16391f
refactor(i18n): Remove unused "disconnect" translation strings
zhb-y-agent Apr 25, 2026
88637e5
fix(i18n): Update connector preview text and layout
zhb-y-agent Apr 25, 2026
f9c77fc
feat(connector): implement lazy loading catalog and large directory p…
zhb-y-agent Apr 25, 2026
1fba24c
feat(connector): implement identity-isolated connector management mec…
zhb-y-agent Apr 25, 2026
087ef8e
docs: add implementation review checklist document
zhb-y-agent Apr 25, 2026
f6403c5
feat(connector): implement connector disconnect and SSO auto-reconnec…
zhb-y-agent Apr 25, 2026
d7b55a7
Merge pull request #312 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
be970de
feat(connector): add catalog search functionality
zhb-y-agent Apr 25, 2026
9736eda
Merge pull request #313 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
31a3a2b
docs: migrate design documents to dev-guides user docs and skills, up…
zhb-y-agent Apr 25, 2026
1cfdaa6
Merge pull request #314 from microsoft/feature/plugin-architecture
zhb-ai Apr 25, 2026
f4de05b
feat(i18n): add row limit warning messages
zhb-y-agent Apr 26, 2026
ababff3
feat(workspace): add lightweight metadata update and list change noti…
zhb-y-agent Apr 26, 2026
49d6fc2
fix(connection error handling): improve connection error message extr…
zhb-y-agent Apr 26, 2026
4b4f592
feat(agent): add reasoning log and knowledge system features
zhb-y-agent Apr 26, 2026
89359d2
feat(workspace): 添加对遗留工作区的自动修复支持
zhb-y-agent Apr 26, 2026
665b3ee
feat(data source): enhance table structure and column description met…
zhb-y-agent Apr 26, 2026
6c09a65
Merge pull request #315 from microsoft/feature/plugin-architecture
zhb-ai Apr 26, 2026
0d193cb
docs: update design documents and add user isolation defense-in-depth…
zhb-y-agent Apr 26, 2026
5e296e3
feat(DataAgent): add reasoning log recording functionality
zhb-y-agent Apr 26, 2026
90343dd
feat(knowledge): implement knowledge management backend functionality
zhb-y-agent Apr 26, 2026
02bdf0e
feat(knowledge system): implement knowledge base integration and expe…
zhb-y-agent Apr 27, 2026
3200934
fix: increase default formulateTimeoutSeconds from 60s to 180s
zhb-y-agent Apr 27, 2026
f9b7443
feat(i18n): add request timeout related error messages
zhb-y-agent Apr 27, 2026
021b480
chore: update .gitignore and remove .vscode/settings.json
zhb-ai Apr 27, 2026
8d30313
feat(logging): refactor ReasoningLogger and ExperienceDistillAgent fo…
zhb-ai Apr 27, 2026
ed5f36e
feat(datetime): establish unified datetime type system and enhance fr…
zhb-ai Apr 27, 2026
5f5ceb0
feat(knowledge): enhance knowledge rules management and introduce limits
zhb-ai Apr 27, 2026
d875252
feat: add date-time type system support
zhb-y-agent Apr 27, 2026
d1f1fdc
fix(experience save): only show save button on final leaf table and c…
zhb-y-agent Apr 27, 2026
a324c06
feat(data display): adjust number formatting based on semantic type
zhb-y-agent Apr 27, 2026
63245d4
feat(knowledge management): improve experience distillation and knowl…
zhb-y-agent Apr 27, 2026
5518355
docs: update multiple development guides and design documents
zhb-y-agent Apr 27, 2026
7091334
feat: add column description support and optimize catalog tree perfor…
zhb-y-agent Apr 27, 2026
4569dd0
feat(knowledge): add type-safe KnowledgeItemMeta class for frontend m…
zhb-y-agent Apr 27, 2026
1bc3294
feat(model support): add vision model support detection functionality
zhb-y-agent Apr 27, 2026
b1e6ad8
feat(recommended questions): add AI generation progress indicator and…
zhb-y-agent Apr 27, 2026
6165adc
docs(agent-knowledge): update design document for reasoning log conte…
zhb-y-agent Apr 27, 2026
1ccac0b
Merge pull request #316 from microsoft/feature/plugin-architecture
zhb-ai Apr 27, 2026
32cd9f4
docs(metadata): design-docs update
zhb-ai Apr 28, 2026
799e6a1
docs: add reference note for development guide 11
zhb-y-agent Apr 28, 2026
25a6bc7
docs: add incremental development rhythm rules document
zhb-y-agent Apr 28, 2026
efac99a
feat(catalog metadata): add catalog metadata synchronization and anno…
zhb-y-agent Apr 28, 2026
82d91b9
feat(catalog): add catalog sync status messages and internationalizat…
zhb-y-agent Apr 28, 2026
bab11ec
refactor(UI): optimize scrollbar styles and add resizable sidebar wid…
zhb-y-agent Apr 28, 2026
342c512
fix(MessageSnackbar): remove unused WarningIcon and use ErrorOutlineI…
zhb-y-agent Apr 28, 2026
dceb4de
feat(interaction strategy): add auto-selection and auto-focus strategies
zhb-y-agent Apr 28, 2026
915c31d
Merge pull request #317 from microsoft/feature/plugin-architecture
zhb-ai Apr 28, 2026
a8efcdb
feat(i18n): add new translations for common actions and enhance exist…
zhb-ai Apr 29, 2026
b5678e3
feat(reporting): enhance report export functionality with image and P…
zhb-ai Apr 29, 2026
2df2c6f
Merge pull request #318 from microsoft/feature/plugin-architecture
zhb-ai Apr 29, 2026
fcb3b3e
feat(clariifcation): implement structured clarification questions and…
zhb-ai Apr 29, 2026
28dd961
Merge pull request #319 from microsoft/feature/plugin-architecture
zhb-ai Apr 29, 2026
85b518b
feat(insight): unify chart insight error handling and timeout configu…
zhb-y-agent Apr 29, 2026
4455d3d
WIP: archive incomplete phase work
zhb-y-agent Apr 30, 2026
59d09e1
feat(error-handling): standardize API error responses and improve err…
zhb-ai Apr 30, 2026
a2efeca
feat(workspace): rename workspace summary endpoint and update naming …
zhb-ai Apr 30, 2026
1630543
feat(error-handling): enhance connector error classification and resp…
zhb-ai Apr 30, 2026
a0340cb
docs: conclude current phase work and update documentation
zhb-y-agent Apr 30, 2026
b92ae9d
feat(frontend state management): implement explicit loading state model
zhb-y-agent Apr 30, 2026
48df290
fix(dfSlice): remove frontend hardcoded timeout and update related do…
zhb-y-agent Apr 30, 2026
4b53bce
feat(i18n): add error messages for model loading failures
zhb-y-agent Apr 30, 2026
55ee4b3
feat(knowledge base): improve experience distillation user experience
zhb-y-agent Apr 30, 2026
59ff27a
feat(catalog tree): optimize virtualization rendering and catalog fet…
zhb-y-agent Apr 30, 2026
e0690ae
fix: fix data catalog tree building and frontend table annotation fet…
zhb-y-agent Apr 30, 2026
53f8859
feat(sandbox): implement cross-call namespace persistent SandboxSession
zhb-y-agent Apr 30, 2026
9393d53
Merge pull request #322 from microsoft/feature/plugin-architecture
zhb-ai Apr 30, 2026
283fd39
fix(security): prevent directory traversal and XSS attacks
zhb-y-agent Apr 30, 2026
7fd637a
refactor: remove type annotations for legacy Python compatibility
zhb-y-agent Apr 30, 2026
464abd5
Merge pull request #323 from microsoft/feature/plugin-architecture
zhb-ai Apr 30, 2026
b18e3cf
fix(security): enhance error handling and sensitive information filte…
zhb-y-agent May 1, 2026
2d4b220
feat(error handling): add error message sanitization and streaming wa…
zhb-y-agent May 1, 2026
6ecdda4
feat(auth): enhance SSO integration security and test coverage
zhb-y-agent May 1, 2026
e9710be
feat(测试): 添加统一docker-compose测试服务和PowerShell管理脚本
zhb-y-agent May 1, 2026
4251221
Merge pull request #324 from microsoft/feature/plugin-architecture
zhb-ai May 1, 2026
aa6ae38
fix(security): enhance log desensitization functionality to support s…
zhb-y-agent May 1, 2026
92ab564
Merge pull request #325 from microsoft/feature/plugin-architecture
zhb-ai May 1, 2026
c52c5da
feat(reasoning_log): add automatic log rotation by date functionality
zhb-y-agent May 1, 2026
fe596c6
docs(knowledge system): add 15.3 knowledge injection and search plann…
zhb-y-agent May 1, 2026
0d34057
feat(元数据同步): 增强目录元数据同步与展示功能
zhb-y-agent May 2, 2026
563e5e7
feat(agents): enhance metadata display with verbose_name and expressi…
zhb-y-agent May 2, 2026
9dcc45b
Merge pull request #326 from microsoft/feature/plugin-architecture
zhb-ai May 2, 2026
58567c8
feat(data loader): add sorting functionality to Superset data loader
zhb-y-agent May 2, 2026
048970f
docs(design-docs): add data loader sorting consistency and identifier…
zhb-y-agent May 2, 2026
1fbe1b2
Merge pull request #327 from microsoft/feature/plugin-architecture
zhb-ai May 2, 2026
37a8661
feat(knowledge system): merge skills and experiences directories into…
zhb-y-agent May 3, 2026
b9d1e64
refactor(knowledge): merge skills and experiences directories into ex…
zhb-y-agent May 3, 2026
2244e46
feat(knowledge distillation): add timeout parameter support for exper…
zhb-y-agent May 3, 2026
93d0369
refactor(knowledge): unify rule injection logic and improve search al…
zhb-y-agent May 3, 2026
e88d282
docs: update document content and structure
zhb-y-agent May 3, 2026
bd04e74
feat(i18n): add Agent log related translations and feature support
zhb-y-agent May 3, 2026
6a9740e
Merge pull request #328 from microsoft/feature/plugin-architecture
zhb-ai May 3, 2026
76330e6
feat(data loading): add AI data assistant functionality and multi-tab…
zhb-y-agent May 4, 2026
db3e4f0
Merge pull request #329 from microsoft/feature/plugin-architecture
zhb-ai May 4, 2026
b948eb3
feat(table): implement pagination and sorting functionality
zhb-y-agent May 5, 2026
6dc04b8
feat: unify data loading row limit and remove frontend row selector
zhb-y-agent May 5, 2026
3a56fae
docs: unify data loading row limit documentation
zhb-y-agent May 5, 2026
45db677
Merge pull request #330 from microsoft/feature/plugin-architecture
zhb-ai May 5, 2026
8be51ae
refactor(data loading): remove rowLimit related code
zhb-y-agent May 5, 2026
7aeef6a
Merge pull request #331 from microsoft/feature/plugin-architecture
zhb-ai May 5, 2026
ea94d8d
update experienes
Chenglong-MS May 6, 2026
79d6707
updates
Chenglong-MS May 7, 2026
1de1328
minor
Chenglong-MS May 7, 2026
d23e85c
refactor(data loading): enhance column metadata handling in SupersetL…
zhb-y-agent May 7, 2026
6c15da2
docs: update SSO OAuth configuration guide and example files
zhb-y-agent May 8, 2026
6d8185a
feat(data loading): update to use Chart Data API for data retrieval
zhb-y-agent May 8, 2026
c3b44e7
clarify+explain
Chenglong-MS May 8, 2026
99c4650
fix some issues with long thread break
Chenglong-MS May 9, 2026
f0975a5
feat(error handling): enhance error message extraction for RTK serial…
zhb-y-agent May 9, 2026
6534fa1
Merge branch 'dev' into feature/plugin-architecture
zhb-ai May 9, 2026
0557b4c
Merge pull request #334 from microsoft/feature/plugin-architecture
zhb-ai May 9, 2026
2e367fc
feat(data loading): add support for temporal column conversion in Sup…
zhb-y-agent May 9, 2026
31b469e
language
Chenglong-MS May 9, 2026
529b545
clarification module update
Chenglong-MS May 9, 2026
2a68c16
update layout algorithm
Chenglong-MS May 9, 2026
5b4aeda
minor
Chenglong-MS May 10, 2026
ca7c5e7
feat(superset): enhance list_tables to include full column metadata v…
zhb-y-agent May 10, 2026
f53b971
fix
Chenglong-MS May 10, 2026
3fa2390
issues: SSO登录态不一致及退出未清空状态问题
zhb-y-agent May 10, 2026
cd2afd4
fixes
Chenglong-MS May 10, 2026
573e6b6
more flexible editing
Chenglong-MS May 11, 2026
45387ea
styling hint
Chenglong-MS May 11, 2026
139b7eb
restyle agent update
Chenglong-MS May 11, 2026
b767bac
ISSUE : refactor agent styling for improved consistency
zhb-y-agent May 11, 2026
b5a71d0
fix ollama issue
Chenglong-MS May 11, 2026
42f0251
some polishment
Chenglong-MS May 11, 2026
9cc1d96
message
Chenglong-MS May 12, 2026
7b436ef
hide issues from main
Chenglong-MS May 12, 2026
3d1a783
remove old design docs
Chenglong-MS May 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
feat(logging): Implement log sanitization to protect sensitive data
- Introduced log sanitization utilities in `log_sanitizer.py` to mask sensitive information in logs, including URLs, parameters, and tokens.
- Updated logging configuration to include a `SensitiveDataFilter` for automatic redaction of sensitive patterns.
- Enhanced logging statements across the application to utilize sanitization functions, ensuring sensitive data is not exposed in logs.
- Added comprehensive tests for log sanitization utilities to verify functionality and edge cases.
  • Loading branch information
zhb-ai committed Apr 24, 2026
commit 17094ecc6898a4d4b9d0dabee5ad912c39d0e573
16 changes: 12 additions & 4 deletions py-src/data_formulator/app.py
Original file line number Diff line number Diff line change
Expand Up @@ -86,10 +86,15 @@ def configure_logging():
log_level_str = os.getenv("LOG_LEVEL", "INFO").strip().upper()
app_log_level = getattr(logging, log_level_str, logging.INFO)

from data_formulator.security.log_sanitizer import SensitiveDataFilter

handler = logging.StreamHandler(sys.stdout)
handler.addFilter(SensitiveDataFilter())

logging.basicConfig(
level=logging.WARNING,
format='%(asctime)s - %(name)s - %(levelname)s - %(message)s',
handlers=[logging.StreamHandler(sys.stdout)]
handlers=[handler],
)

logging.getLogger('data_formulator').setLevel(app_log_level)
Expand All @@ -99,10 +104,13 @@ def configure_logging():
logging.getLogger('openai').setLevel(logging.WARNING)

app.logger.handlers = []
for handler in logging.getLogger().handlers:
app.logger.addHandler(handler)
for h in logging.getLogger().handlers:
app.logger.addHandler(h)

logging.getLogger('data_formulator').info(f"Log level: {log_level_str}")
logging.getLogger('data_formulator').info(
"Log level: %s (sanitize=%s)", log_level_str,
os.getenv("LOG_SANITIZE", "true"),
)


_blueprints_registered = False
Expand Down
3 changes: 2 additions & 1 deletion py-src/data_formulator/auth/gateways/github_gateway.py
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,8 @@ def github_callback():
"raw_token": access_token,
"provider": "github",
}
logger.info("GitHub login successful: user=%s (%s)", login, user_id)
logger.info("GitHub login successful: user=%s (id=%s...)",
login, user_id[:8] if len(user_id) > 8 else user_id)

return redirect("/")

Expand Down
18 changes: 11 additions & 7 deletions py-src/data_formulator/auth/providers/oidc.py
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@
from flask import Flask, Request

from .base import AuthProvider, AuthResult, AuthenticationError
from data_formulator.security.log_sanitizer import sanitize_url, redact_token

logger = logging.getLogger(__name__)

Expand Down Expand Up @@ -115,13 +116,14 @@ def _try_discovery(self, discovery_url: str) -> dict[str, Any] | None:
logger.warning(
"Discovery response from %s missing authorization_endpoint "
"(likely not a valid discovery document), ignoring",
discovery_url,
sanitize_url(discovery_url),
Comment thread Dismissed
)
return None

return doc
except Exception as exc:
logger.warning("Discovery request failed for %s: %s", discovery_url, exc)
logger.warning("Discovery request failed for %s: %s",
sanitize_url(discovery_url), type(exc).__name__)
Comment thread Dismissed
return None

def on_configure(self, app: Flask) -> None:
Expand Down Expand Up @@ -160,7 +162,7 @@ def on_configure(self, app: Flask) -> None:
if "id_token_signing_alg_values_supported" in discovery:
self._algorithms = discovery["id_token_signing_alg_values_supported"]
self._discovery_ok = True
logger.info("Discovery succeeded for issuer %s", self._issuer)
logger.info("Discovery succeeded for issuer %s", sanitize_url(self._issuer))
else:
logger.warning(
"All discovery attempts failed — using manual endpoints"
Expand All @@ -170,18 +172,20 @@ def on_configure(self, app: Flask) -> None:
if self._jwks_url:
try:
self._jwks_client = PyJWKClient(self._jwks_url, cache_keys=True)
logger.info("JWKS client initialised: %s", self._jwks_url)
logger.info("JWKS client initialised: %s", sanitize_url(self._jwks_url))
except Exception as exc:
logger.warning("Failed to initialise JWKS client: %s", exc)
logger.warning("Failed to initialise JWKS client: %s", type(exc).__name__)

# 3) Summarise
mode = "JWKS" if self._jwks_client else (
"userinfo" if self._userinfo_url else "NONE"
)
logger.info(
"OIDC provider ready: issuer=%s, client_id=%s, "
"OIDC provider ready: issuer=%s, client_id=%s..., "
"protocol=%s, discovery=%s, token_validation=%s",
self._issuer, self._client_id, self._protocol,
sanitize_url(self._issuer),
self._client_id[:4] + "..." if len(self._client_id) > 4 else self._client_id,
self._protocol,
"ok" if self._discovery_ok else "manual",
mode,
)
Expand Down
3 changes: 2 additions & 1 deletion py-src/data_formulator/data_loader/mssql_data_loader.py
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,8 @@ def auth_instructions() -> str:
**Troubleshooting:** Ensure SQL Server service is running. Verify TCP/IP is enabled in SQL Server Configuration Manager. Test with `sqlcmd -S <server> -d <database> -U <user> -P <password>`."""

def __init__(self, params: dict[str, Any]):
log.info(f"Initializing MSSQL DataLoader with parameters: {params}")
from data_formulator.security.log_sanitizer import sanitize_params
log.info("Initializing MSSQL DataLoader with parameters: %s", sanitize_params(params))

self.params = params

Expand Down
4 changes: 3 additions & 1 deletion py-src/data_formulator/routes/agents.py
Original file line number Diff line number Diff line change
Expand Up @@ -170,8 +170,10 @@ def check_available_models():
all_public = model_registry.list_public()
logger.info("=" * 60)
logger.info(f"[check-available-models] Checking {len(all_public)} global models")
from data_formulator.security.log_sanitizer import sanitize_url
for p in all_public:
logger.info(f" -> {p['id']} (endpoint={p['endpoint']}, model={p['model']}, api_base={p['api_base']})")
logger.info(" -> %s (endpoint=%s, model=%s, api_base=%s)",
p['id'], p['endpoint'], p['model'], sanitize_url(p.get('api_base', '')))
overall_start = time.time()

def _check_one(public_info: dict) -> dict:
Expand Down
202 changes: 202 additions & 0 deletions py-src/data_formulator/security/log_sanitizer.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,202 @@
# Copyright (c) Microsoft Corporation.
# Licensed under the MIT License.

"""Log sanitization utilities for preventing sensitive data leakage.

Provides two layers of defense:

1. **Explicit utilities** — ``sanitize_url``, ``sanitize_params``,
``redact_token`` — called at logging call-sites for precise control.

2. **SensitiveDataFilter** — a ``logging.Filter`` registered on handlers
as a safety net, automatically redacting patterns that slip through.

Usage::

from data_formulator.security.log_sanitizer import (
sanitize_url, sanitize_params, redact_token,
)

logger.info("Connected to %s", sanitize_url(url))
logger.info("Params: %s", sanitize_params(params))
logger.debug("Token: %s", redact_token(token))

The filter is registered in ``app.py:configure_logging()`` and can be
disabled via ``LOG_SANITIZE=false`` for local debugging.
"""

from __future__ import annotations

import copy
import logging
import os
import re
from typing import Any

# ---------------------------------------------------------------------------
# Sensitive key names (case-insensitive matching)
# ---------------------------------------------------------------------------

SENSITIVE_KEYS: frozenset[str] = frozenset({
"password", "passwd", "pwd",
"secret", "client_secret",
"token", "access_token", "refresh_token",
"api_key", "apikey", "api-key",
"access_key", "secret_key", "secret_access_key",
"credential", "credentials",
"private_key", "private-key",
"authorization",
"connection_string", "conn_str",
})

_REDACTED = "***"
_REDACTED_TOKEN = "[REDACTED]"

# ---------------------------------------------------------------------------
# Pre-compiled regex patterns for the safety-net filter
# ---------------------------------------------------------------------------

# URL with embedded credentials: ://user:password@host
_RE_URL_CREDS = re.compile(
r"(://[^/:@\s]+:)[^/@\s]+(@)",
)

# key=value patterns (password=xxx, api_key=xxx, secret=xxx, etc.)
_SENSITIVE_KEY_NAMES = (
r"password|passwd|pwd|secret|client_secret"
r"|token|access_token|refresh_token"
r"|api_key|apikey|api[-_]key"
r"|access_key|secret_key|secret_access_key"
r"|credential|credentials"
r"|private_key|private[-_]key"
r"|authorization"
r"|connection_string|conn_str"
)
_RE_KEY_VALUE = re.compile(
rf"({_SENSITIVE_KEY_NAMES})" # group 1: key name
r"(\s*[=:]\s*)" # group 2: separator (= or :)
r"(\S+)", # group 3: value
re.IGNORECASE,
)

# Bearer token: Bearer eyJxxx... (long opaque strings)
_RE_BEARER = re.compile(
r"(Bearer\s+)\S{12,}",
re.IGNORECASE,
)

# Bare JWT-like strings: eyJ followed by 28+ base64url chars
_RE_JWT_LIKE = re.compile(
r"\beyJ[A-Za-z0-9_-]{28,}",
)

# Python dict repr with sensitive keys: 'password': 'value' or "password": "value"
_RE_DICT_SENSITIVE = re.compile(
rf"""(['"])({_SENSITIVE_KEY_NAMES})\1""" # quoted key
r"""(\s*:\s*)""" # colon separator
r"""(['"])(.+?)\4""", # quoted value
re.IGNORECASE,
)


# ---------------------------------------------------------------------------
# Explicit utility functions (Layer 1)
# ---------------------------------------------------------------------------

def sanitize_url(url: str) -> str:
"""Mask credentials embedded in a URL.

``https://user:s3cret@host/path`` → ``https://user:***@host/path``

Safe to call on URLs without credentials (returns unchanged).
"""
if not url or "://" not in url:
return url
return _RE_URL_CREDS.sub(rf"\g<1>{_REDACTED}\2", url)


def sanitize_params(params: dict[str, Any],
extra_keys: frozenset[str] | set[str] | None = None,
) -> dict[str, Any]:
"""Return a shallow copy of *params* with sensitive values masked.

Keys are matched case-insensitively against ``SENSITIVE_KEYS``
(plus *extra_keys* when provided).
"""
keys_to_mask = SENSITIVE_KEYS | (extra_keys or frozenset())
sanitized = {}
for k, v in params.items():
if k.lower() in keys_to_mask:
sanitized[k] = _REDACTED
elif isinstance(v, dict):
sanitized[k] = sanitize_params(v, extra_keys)
else:
sanitized[k] = v
return sanitized


def redact_token(token: str, visible: int = 4) -> str:
"""Abbreviate a token to first/last *visible* characters.

Short tokens (≤ 2×visible) are fully masked.

``"eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.xxx"``
→ ``"eyJh...eCJ9"`` (visible=4)
"""
if not token:
return ""
if len(token) <= visible * 2:
return _REDACTED_TOKEN
return f"{token[:visible]}...{token[-visible:]}"


# ---------------------------------------------------------------------------
# SensitiveDataFilter — logging.Filter safety net (Layer 2)
# ---------------------------------------------------------------------------

def _apply_patterns(text: str) -> str:
"""Run all redaction patterns on *text* and return the sanitized version."""
# Order matters: most specific patterns first to avoid partial matches.
text = _RE_URL_CREDS.sub(rf"\g<1>{_REDACTED}\2", text)
text = _RE_BEARER.sub(rf"\g<1>{_REDACTED_TOKEN}", text)
text = _RE_KEY_VALUE.sub(rf"\g<1>\g<2>{_REDACTED}", text)
text = _RE_DICT_SENSITIVE.sub(
rf"\g<1>\g<2>\g<1>\g<3>\g<4>{_REDACTED}\g<4>",
text,
)
text = _RE_JWT_LIKE.sub(_REDACTED_TOKEN, text)
return text


class SensitiveDataFilter(logging.Filter):
"""Safety-net filter that auto-redacts sensitive patterns in log messages.

Attach to handlers in ``configure_logging()``::

handler.addFilter(SensitiveDataFilter())

Disable at runtime via ``LOG_SANITIZE=false``.
"""

def filter(self, record: logging.LogRecord) -> bool:
if os.environ.get("LOG_SANITIZE", "true").strip().lower() in (
"false", "0", "no",
):
return True

# Format %-style args into the message so we can scan the full string.
# After formatting we clear args to prevent double-formatting by the
# handler's Formatter.
if record.args:
try:
record.msg = record.msg % record.args
record.args = None
except (TypeError, ValueError):
pass

record.msg = _apply_patterns(str(record.msg))

if record.exc_text:
record.exc_text = _apply_patterns(record.exc_text)

return True
Loading