Skip to content

ACP permission cache key null-byte collision vector #872

@bug-ops

Description

@bug-ops

Context

Tool names from acp-permissions.toml inserted into cache without stripping null bytes. Cache key format {session_id}\0{tool_name} could collide.

Solution

Filter null bytes from tool names when loading persisted permissions.

Epic: #854 | Effort: S | Crate: zeph-acp

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions