feat: stateless AES-256-GCM crypto tokens with SSE-aware detokenization
Replace the in-memory token map with self-contained cryptographic tokens. ggshield-flagged secrets are encrypted with AES-256-GCM under a persistent 256-bit master key; the placeholder carries IV ++ authTag ++ ciphertext as hex, so the proxy is stateless and resolves tokens across restarts and replayed chat histories. The streaming detokenizer now parses SSE content_block_delta events and reassembles placeholders fragmented across many deltas — a raw byte scan can't bridge the interleaved event/JSON framing. Plain JSON responses keep the simpler contiguous byte scan. The master key is generated 0600 on first run at ~/.config/claude-tokenization-proxy/master.key (override GG_MASTER_KEY_FILE); deleting it makes existing tokens unrecoverable.
This commit is contained in:
@@ -18,3 +18,7 @@ node_modules/
|
||||
|
||||
# ggshield local cache
|
||||
.cache_ggshield
|
||||
|
||||
# Master key — never commit (default lives in ~/.config, but guard the project root)
|
||||
master.key
|
||||
*.master.key
|
||||
|
||||
Reference in New Issue
Block a user