Harden logging: redact sensitive headers/bodies and add redaction helper + tests - #4
Open
heliosran wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Description
src/log_redaction.ts) exposingmaskSecret,redactForLogging, andredactHeadersForLoggingthat masks token-like values (preserve last 4 chars) and recognizes common sensitive header/key names.src/upstream.tsto use the redaction helpers and agetSanitizedRequestBodyForLogginghelper; error and failure logs now redact bodies and headers and only emit full (but redacted) diagnostics whenenv.VERBOSE === "true", ensuring secrets are never printed even in verbose mode.src/auth_kv.tstoken-refresh logging to avoid printing the fullrefreshRequestand instead emit non-sensitive metadata (status, endpoint, correlation id), with optional verbose diagnostics that still use the redacted headers.test/log_redaction.spec.tsto validatemaskSecretbehavior and recursive/key-based redaction, including header normalization.Testing
npm run tscand lint withnpm run lint, both succeeded.npm test, which fails in this environment due to the repo’s Vitest Workers config expectingwrangler.jsonc(environment-specific config), so that run reported a config-related error.npx vitest --run --config vitest.unit.config.mts, and thetest/log_redaction.spec.tssuite passed (3 tests).Codex Task