joeyutong commented on code in PR #1185:
URL: https://github.com/apache/flink-agents/pull/1185#discussion_r4229567301


##########
runtime/src/main/java/org/apache/flink/agents/runtime/eventlog/ChatMessageEventLogSerializer.java:
##########
@@ -47,7 +48,26 @@ public class ChatMessageEventLogSerializer extends 
JsonSerializer<ChatMessage> {
     /** The module Event Log mappers register to apply the sanitized {@link 
ChatMessage} shape. */
     public static Module module() {
         return new SimpleModule("flink-agents-event-log-chat-messages")
-                .addSerializer(ChatMessage.class, new 
ChatMessageEventLogSerializer());
+                .addSerializer(ChatMessage.class, new 
ChatMessageEventLogSerializer())
+                .addSerializer(
+                        ChatResult.class,

Review Comment:
   When a tool returns media via the new `ToolResponse.blocks`, 
`ToolResponseEvent` logs those blocks without calling `sanitize()`: this module 
only registers `ChatMessage` and `ChatResult`. Inline payloads and source URLs 
(including credentials or signed query parameters) can therefore enter the log. 
The later `ChatMessage` sanitization does not protect this earlier event.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to