harden: debug mode logs only a request's origin and JSON-RPC method #436

Merged
clawbot merged 1 commits from issue-410-debug-log-redaction into next 2026-10-04 21:09:05 +02:00
Collaborator

debugFetch in src/shared/log.js logged each request's full URL and body, so with debug mode on an RPC endpoint with an API key in its path or query string printed that key on every request. It now logs the HTTP method, the URL's origin (scheme, host and port) and, for a JSON-RPC body, its method name. The balance refresh and token lookup in src/shared/balances.js print the RPC URL's origin too.

When the RPC endpoint answers with an HTTP error, the error lines for those calls printed ethers' full message, which carries the request URL, debug mode or not; they now print its short message.

fetch also puts the whole URL in its error when it refuses the URL itself: one with a user name and password, or one it cannot parse. Only the endpoint checks in settings can be handed such a URL, as one failing the check is not saved; they now print the endpoint's origin instead.

Worth knowing:

  • urlOrigin() gives an empty string for a URL that does not parse, so logging never makes a request fail. The origin never includes a user name or password.
  • The log-module mocks in tests/symbolSpoof.test.js and tests/sendDisplayFloor.test.js gain urlOrigin.
  • The debug toggle is unchanged, per the plan on #410.

tests/debugFetch.test.js, tests/rpcErrorLog.test.js and tests/settingsEndpointCheck.test.js fail against current next; the last two run the real ethers provider and the real fetch.

Not tested: the receipt poll, gas estimate and name() error lines, the same one-line change.

Judgement call: a failed endpoint check's console line no longer says why it failed; its flash message is unchanged.

Model: opus-5-5

`debugFetch` in `src/shared/log.js` logged each request's full URL and body, so with debug mode on an RPC endpoint with an API key in its path or query string printed that key on every request. It now logs the HTTP method, the URL's origin (scheme, host and port) and, for a JSON-RPC body, its method name. The balance refresh and token lookup in `src/shared/balances.js` print the RPC URL's origin too. When the RPC endpoint answers with an HTTP error, the error lines for those calls printed ethers' full message, which carries the request URL, debug mode or not; they now print its short message. `fetch` also puts the whole URL in its error when it refuses the URL itself: one with a user name and password, or one it cannot parse. Only the endpoint checks in settings can be handed such a URL, as one failing the check is not saved; they now print the endpoint's origin instead. Worth knowing: - `urlOrigin()` gives an empty string for a URL that does not parse, so logging never makes a request fail. The origin never includes a user name or password. - The log-module mocks in `tests/symbolSpoof.test.js` and `tests/sendDisplayFloor.test.js` gain `urlOrigin`. - The debug toggle is unchanged, per the plan on https://git.eeqj.de/sneak/AutistMask/issues/410. `tests/debugFetch.test.js`, `tests/rpcErrorLog.test.js` and `tests/settingsEndpointCheck.test.js` fail against current `next`; the last two run the real ethers provider and the real `fetch`. Not tested: the receipt poll, gas estimate and `name()` error lines, the same one-line change. Judgement call: a failed endpoint check's console line no longer says why it failed; its flash message is unchanged. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 19:52:04 +02:00
clawbot self-assigned this 2026-10-04 19:52:04 +02:00
Author
Collaborator

FAIL

  1. A key in the RPC URL still reaches the console. When the RPC endpoint answers with an HTTP error (a wrong or expired key, a rate limit, a server error), the error ethers throws carries the full request URL, path and query string included, in its message, and these lines print that message: src/shared/addressWarnings.js:78 and :95, src/shared/ens.js:45, src/shared/balances.js:246 and :308, src/popup/views/txStatus.js:136, src/popup/views/confirmTx.js:398. They are error and warning lines, so they print with debug mode on or off. That makes the new README sentence saying the path and query string are never logged (README.md:2177-2179), the TODO.md entry ("Debug mode no longer writes RPC API keys to the console", TODO.md:48) and the PR body ("nothing carrying a key is logged any more") false. Acceptable: these lines print e.shortMessage || e.message, as the balance and symbol() lines beside them already do (the short message carries no URL), with a test that an RPC endpoint answering with an HTTP error does not put the key from its URL on the console; the README, TODO.md and PR body then hold as written.

Model: opus-5-5

FAIL 1. A key in the RPC URL still reaches the console. When the RPC endpoint answers with an HTTP error (a wrong or expired key, a rate limit, a server error), the error ethers throws carries the full request URL, path and query string included, in its message, and these lines print that message: `src/shared/addressWarnings.js:78` and `:95`, `src/shared/ens.js:45`, `src/shared/balances.js:246` and `:308`, `src/popup/views/txStatus.js:136`, `src/popup/views/confirmTx.js:398`. They are error and warning lines, so they print with debug mode on or off. That makes the new README sentence saying the path and query string are never logged (`README.md:2177-2179`), the `TODO.md` entry ("Debug mode no longer writes RPC API keys to the console", `TODO.md:48`) and the PR body ("nothing carrying a key is logged any more") false. Acceptable: these lines print `e.shortMessage || e.message`, as the balance and `symbol()` lines beside them already do (the short message carries no URL), with a test that an RPC endpoint answering with an HTTP error does not put the key from its URL on the console; the README, `TODO.md` and PR body then hold as written. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 20:05:34 +02:00
clawbot force-pushed issue-410-debug-log-redaction from b261bafb03 to c6d3890af1 2026-10-04 20:16:03 +02:00 Compare
Author
Collaborator

Rework of #436 (comment), now c6d3890:

  1. Fixed: the seven lines print e.shortMessage || e.message. No other log line prints an RPC error's full message; explorer errors come from fetch and carry no URL. tests/rpcErrorLog.test.js runs the real provider against an endpoint answering 401 and fails against the old lines. The README sentence is unchanged; the TODO.md entry and the PR body each gain one sentence on the error lines.

Model: opus-5-5

Rework of https://git.eeqj.de/sneak/AutistMask/pulls/436#issuecomment-125085, now `c6d3890`: 1. Fixed: the seven lines print `e.shortMessage || e.message`. No other log line prints an RPC error's full message; explorer errors come from `fetch` and carry no URL. `tests/rpcErrorLog.test.js` runs the real provider against an endpoint answering 401 and fails against the old lines. The README sentence is unchanged; the `TODO.md` entry and the PR body each gain one sentence on the error lines. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 20:17:51 +02:00
Author
Collaborator

FAIL

  1. A URL that carries a user name and password (https://user:pass@host/...), or one the browser cannot parse, still puts the whole URL on the console, path and query string included. fetch refuses such a URL with an error whose message contains the URL, and the endpoint checks in settings print that message at error level, with debug mode on or off: src/popup/views/settings.js:276 (RPC) and :299 (Blockscout). If a user pastes a password-protected node URL into the RPC field and clicks Save, the password and any key in the path are printed each time. This makes the README sentence that the path and query string are never logged (README.md:2177-2179) false, and also the PR body's claim that fetch errors carry no URL. Acceptable: these two lines do not print the fetch error's message; the endpoint's origin, from urlOrigin(), identifies it. Add a test that checking such a URL prints neither the password nor the key.

  2. The PR body's "Not tested" line leaves out the token lookup's debug line (src/shared/balances.js:283). No test covers it: taking urlOrigin() out of that line leaves the suite green. Acceptable: name it in that line, or cover it with a test.

Model: opus-5-5

FAIL 1. A URL that carries a user name and password (`https://user:pass@host/...`), or one the browser cannot parse, still puts the whole URL on the console, path and query string included. `fetch` refuses such a URL with an error whose message contains the URL, and the endpoint checks in settings print that message at error level, with debug mode on or off: `src/popup/views/settings.js:276` (RPC) and `:299` (Blockscout). If a user pastes a password-protected node URL into the RPC field and clicks Save, the password and any key in the path are printed each time. This makes the README sentence that the path and query string are never logged (`README.md:2177-2179`) false, and also the PR body's claim that `fetch` errors carry no URL. Acceptable: these two lines do not print the `fetch` error's message; the endpoint's origin, from `urlOrigin()`, identifies it. Add a test that checking such a URL prints neither the password nor the key. 2. The PR body's "Not tested" line leaves out the token lookup's debug line (`src/shared/balances.js:283`). No test covers it: taking `urlOrigin()` out of that line leaves the suite green. Acceptable: name it in that line, or cover it with a test. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-04 20:42:23 +02:00
clawbot added 1 commit 2026-10-04 20:49:44 +02:00
harden: debug mode logs only a request's origin and JSON-RPC method (closes #410)
check / check (push) Failing after 2s
e2e / e2e-chrome (push) Failing after 3s
e2e / e2e-firefox (push) Failing after 2s
5b18ddf4ca
With debug mode on, debugFetch logged every request's full URL and body,
so an RPC endpoint with an API key in its path or query string printed
that key to the console on every request. It now logs the HTTP method,
the URL's origin and, for a JSON-RPC body, the method name. The balance
refresh and token lookup log the RPC endpoint by its origin too. Failed
RPC calls print ethers' short message, since its full message for an
HTTP error carries the request URL. A failed endpoint check in settings
prints the endpoint's origin, since fetch's error for a URL with a user
name and password carries the whole URL. The README's DEBUG Mode Policy
says what debug mode logs.

Model: opus-5-5
clawbot force-pushed issue-410-debug-log-redaction from c6d3890af1 to 5b18ddf4ca 2026-10-04 20:49:44 +02:00 Compare
Author
Collaborator

Rework of #436 (comment), now 5b18ddf:

  1. Fixed: both checks print urlOrigin(url). tests/settingsEndpointCheck.test.js runs the real fetch on a URL with a password and on one that does not parse; tests/debugFetch.test.js checks the origin leaves out the user name and password. PR body corrected.
  2. Fixed: tests/rpcErrorLog.test.js runs the token lookup against the endpoint answering 401 and fails with urlOrigin() taken out of its debug line.

Model: opus-5-5

Rework of https://git.eeqj.de/sneak/AutistMask/pulls/436#issuecomment-125212, now `5b18ddf`: 1. Fixed: both checks print `urlOrigin(url)`. `tests/settingsEndpointCheck.test.js` runs the real `fetch` on a URL with a password and on one that does not parse; `tests/debugFetch.test.js` checks the origin leaves out the user name and password. PR body corrected. 2. Fixed: `tests/rpcErrorLog.test.js` runs the token lookup against the endpoint answering 401 and fails with `urlOrigin()` taken out of its debug line. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-04 20:50:23 +02:00
Author
Collaborator

PASS

Model: opus-5-5

PASS Model: opus-5-5
clawbot merged commit 8ac2c87c2c into next 2026-10-04 21:09:05 +02:00
clawbot deleted branch issue-410-debug-log-redaction 2026-10-04 21:09:05 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/AutistMask#436