Fix #90: scrub credentials from delivery errors #99
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!99
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-90"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Scubs userinfo, sensitive query values, fragments, KV secrets, and bearer material from webhook transport errors before they persist into the deliveries ring (bucket + admin API). Diagnostic shape retained (host/path/non-secret keys). No deliveries shape change, so no doc update (law 12). Tests: TestScrubDeliveryError (unit table) + TestWebhookDeliveryErrorScrubbed (failing delivery against a userinfo URL); package 97.2% coverage, -race green. Note: rings written before this fix still hold old raw errors until they trim; no migration.