Fix #90: scrub credentials from delivery errors #99

Merged
crueber merged 1 commit from fix/issue-90 into main 2026-09-05 02:45:48 +00:00
Owner

Scubs userinfo, sensitive query values, fragments, KV secrets, and bearer material from webhook transport errors before they persist into the deliveries ring (bucket + admin API). Diagnostic shape retained (host/path/non-secret keys). No deliveries shape change, so no doc update (law 12). Tests: TestScrubDeliveryError (unit table) + TestWebhookDeliveryErrorScrubbed (failing delivery against a userinfo URL); package 97.2% coverage, -race green. Note: rings written before this fix still hold old raw errors until they trim; no migration.

Scubs userinfo, sensitive query values, fragments, KV secrets, and bearer material from webhook transport errors before they persist into the deliveries ring (bucket + admin API). Diagnostic shape retained (host/path/non-secret keys). No deliveries shape change, so no doc update (law 12). Tests: TestScrubDeliveryError (unit table) + TestWebhookDeliveryErrorScrubbed (failing delivery against a userinfo URL); package 97.2% coverage, -race green. Note: rings written before this fix still hold old raw errors until they trim; no migration.
recordDelivery persisted raw derr.Error() into the deliveries ring;
Go transport errors echo the hook URL, leaking userinfo and query
tokens to the bucket + admin API. Scrub userinfo, sensitive query
values, fragments, KV secrets, and bearer material before storing;
diagnostic shape (host/path/non-secret keys) retained. No deliveries
shape change (Error stays string), so no doc update (law 12).
Sign in to join this conversation.
No description provided.