(value: unknown)
| 214 | * these constraints without coupling to the UUID format. |
| 215 | */ |
| 216 | export function isSafeTaskId(value: unknown): value is string { |
| 217 | // Stable token (alphanumeric plus . _ : -, 1-64 chars) AND redaction-stable: |
| 218 | // the id is rendered verbatim, so a secret-shaped id (ghp_..., sk-..., a |
| 219 | // 40-char hex, AIza...) must be rejected -- otherwise a renderer that does |
| 220 | // run redactSecrets would turn it into [redacted] while the store keeps the |
| 221 | // real id, and a later task_update would miss. |
| 222 | return ( |
| 223 | typeof value === 'string' && |
| 224 | /^[A-Za-z0-9][A-Za-z0-9._:-]{0,63}$/.test(value) && |
| 225 | redactSecrets(value) === value |
| 226 | ); |
| 227 | } |
| 228 | |
| 229 | export function isTaskKey(value: unknown): value is string { |
| 230 | return ( |
no test coverage detected