Skip to content

fixture (0.26.0) misses JSON-escaped Windows home paths (C:\\Users\\<name>) in draft_meta_info.json #134

Description

@fpisasale

Environment: capcut-cli 0.26.0, CapCut desktop 8.7.0, Windows 11.

capcut fixture <project> --out <dir> reported 36 redactions (windows_user_fwd, windows_user, device_ids, macos_user). The real Windows username nevertheless survived in draft_meta_info.json, in the draft_root_path value. In the raw file it is stored with JSON-escaped backslashes:

"draft_root_path":"C:\\Users\\<real-name>\\AppData\\Local\\CapCut\\User Data\\Projects\\com.lveditor.draft"

Forward-slash paths (C:/Users/<name>/…) were all redacted correctly. Only this escaped-backslash form slipped through.

Expected: the bundle contains no real username.

Suggestion: redact on parsed JSON string values, or match \\\\Users\\\\<name> on the raw text as well. A final check on the bundle for the current USERNAME / os.userInfo().username would also catch it.

We redacted the value by hand before sharing our bundle (see #50, https://gist.github.com/fpisasale/8b344dccd4f4a731a35ef49ca55f0ff0).

— Spirito Digitale

Activity

  1. renezander030 commented on Oct 3, 2026

    @renezander030
    Owner

    Thanks @fpisasale, especially for manually reviewing and redacting the bundle before sharing it. The current Windows-path redactor only matches single backslashes, so JSON-escaped paths can survive.

    I’m fixing escaped paths, including paths inside JSON strings, and making the existing redaction verification run automatically when a bundle is created. The command will fail its check if recognizable private values remain. Until that patch ships, use capcut fixture <project> --out <dir> --check and inspect the output before sharing.

    My earlier statements in #50 that the fixture command was safe to run were too broad. The device-ID fix did not establish complete path redaction, and this report demonstrates the gap.

  2. renezander030 commented on Oct 3, 2026

    @renezander030
    Owner

    The redaction fix is in draft PR #135: #135

    JSON-escaped Windows home paths are redacted while preserving the surrounding JSON, including embedded JSON strings. Every new bundle now runs residual-value verification automatically. Findings make the CLI exit nonzero and are recorded in SANITIZE_REPORT.json; the check reports file and line without echoing the private value. The scan also catches later home paths on the same line and short/Unicode account names.

    Regression tests and the full local suite pass (1,017 tests). Please re-run fixture creation on your project with the PR and inspect draft_root_path and the generated reports. The patch remains a draft for review.

  3. renezander030 commented on Oct 3, 2026

    @renezander030
    Owner

    Released in v0.26.1, available on npm:

    npm install -g capcut-cli@0.26.1

    The fresh packaged install was checked for escaped Windows paths both in ordinary JSON and embedded JSON strings. Bundle creation now runs residual-value verification automatically; recognizable leaks cause a nonzero exit and a failed SANITIZE_REPORT.json. fixture <bundle> --check still checks an existing bundle, and findings do not echo the private value. All 1,017 tests and platform CI passed.

    See the fixture verification steps. Thanks again for identifying the leaked field.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions