fix(catalog): drop the ChatGPT session token from the cloro example; ignore its fingerprint

gitleaks flagged a `resume_conversation_token` JWT inside the captured ChatGPT rawResponse: a
browser-session artifact of the cloro-run tab, exactly the kind the capture rule says to drop.
Removed from the example; the historical fingerprint is listed in .gitleaksignore because the
branch is shared and rewriting it would clobber concurrent work.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019NxnhmtLJ2pasdfSAtuP5C
This commit is contained in:
Jason Zhou
2026-09-14 10:49:09 +10:00
co-authored by Claude Fable 5.1
parent 732d48d80a
commit 577bb2407c
2 changed files with 5 additions and 6 deletions
+5
View File
@@ -0,0 +1,5 @@
# Fingerprints gitleaks skips. One per line: <commit>:<file>:<rule>:<line>.
# A ChatGPT `resume_conversation_token` (a browser-session JWT for the cloro-run ChatGPT tab, which
# expires within minutes and authorises nothing of treg's) rode into the captured example in this
# commit; the file was scrubbed in the next commit, the value stays only in history.
bff917ce05ca9c77169205c73da9f02f734a7e33:src/treg/catalog/examples/cloro.ai-search.chatgpt.scrape.json:jwt:56
@@ -50,12 +50,6 @@
],
"mapSearchQueries": [],
"rawResponse": [
{
"type": "resume_conversation_token",
"kind": "topic",
"token": "eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCJ9.eyJjb25kdWl0X3V1aWQiOiJkMGFkMDdhOWQ4ZmM0NDQ4YjBlZDA5YmNiOWI4YTJmYiIsImNvbmR1aXRfbG9jYXRpb24iOiIxMC4xMjguMjExLjE1Mzo4MzAzIiwiY2x1c3RlciI6InVuaWZpZWQtNDEiLCJpYXQiOjE3ODg3NjIwMjcsImV4cCI6MTc4ODc3NjQyNywidHVybl90b3BpY19pZCI6ImNvbnZlcnNhdGlvbi10dXJuLWQ3MThhYjBmLWQ0YzUtNDc5Yi1iYzI1LTFiYWUyZDZiZGQ2YSJ9.s_jrKeQGnR6leB48nTSaKELpTl3pInRvKJWSjyL56dNgWA4NtskIgUcbliNIygDv4amv8D86gnNSHH7CToiKRQ",
"conversation_id": "6a9e57aa-3778-83ea-bb52-ba40f10197f8"
},
{
"p": "",
"o": "add",