mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-11 22:12:23 +00:00
32d5972673
Governed resources (every sensitive guest) were redacted to a terse summary on cloud-routed Assistant turns, so the Assistant went blind on cloud models -- generic non-answers for the majority of users who run cloud providers. Add AIConfig.ShareOperationalContextWithCloud (default false). When the operator opts in and the turn routes to an external provider, the chat prefetch path injects servicediscovery.FormatCloudSafeContext (service identity, access command, config/data/log paths, ports -- PII-free) in place of the terse governed redaction, and the model-bound resource sanitizer allow-lists those exact spans so they survive the provider boundary. Hostname/IP/alias/platform-id stay redacted regardless of the opt-in. When sharing is off on a cloud turn, the prefetch path instructs the Assistant to disclose the redaction and point at the setting instead of silently degrading the answer. Local (Ollama) routing is unaffected and always receives full context. Proof: internal/ai/chat/context_prefetch_cloud_context_test.go (opt-in => access path present, no hostname/IP; opt-out => governed redaction + transparency; model-bound sanitizer strips raw PII while the allow-listed cloud-safe span survives) and internal/config/ai_config_test.go. ai-runtime contract updated for the new opt-in behavior.