harden: debug mode logs only a request's origin and JSON-RPC method (closes #410)
With debug mode on, debugFetch logged every request's full URL and body, so an RPC endpoint with an API key in its path or query string printed that key to the console on every request. It now logs the HTTP method, the URL's origin and, for a JSON-RPC body, the method name. The balance refresh and token lookup log the RPC endpoint by its origin too. Failed RPC calls print ethers' short message, since its full message for an HTTP error carries the request URL. A failed endpoint check in settings prints the endpoint's origin, since fetch's error for a URL with a user name and password carries the whole URL. The README's DEBUG Mode Policy says what debug mode logs. Model: opus-5-5
This commit was merged in pull request #436.
This commit is contained in:
@@ -2168,6 +2168,17 @@ the log level and turns the banner on, and that is all it may ever do: it feeds
|
||||
constant directly, so no runtime toggle in a release build can reach the
|
||||
hardcoded test phrase.
|
||||
|
||||
At the raised log level the console also shows the wallet's addresses with their
|
||||
balances and ENS names, the token contracts looked up, and a line for each
|
||||
request made through `debugFetch` in `src/shared/log.js` (the explorer, the
|
||||
price feed, the RPC calls a site makes, and the endpoint checks in settings) and
|
||||
for its response. A request is logged by its HTTP method, the origin of its URL
|
||||
(scheme, host and port) and, for a JSON-RPC call, the method name; the balance
|
||||
refresh, the token lookup and a failed endpoint check in settings name the
|
||||
endpoint by its origin too. The URL's path and query string, where RPC providers
|
||||
put API keys, any user name and password in it, and the request body are never
|
||||
logged.
|
||||
|
||||
### Key Decisions
|
||||
|
||||
- **No framework**: The popup UI is vanilla JS and HTML. The extension is small
|
||||
|
||||
Reference in New Issue
Block a user