// What debugFetch writes to the console in debug mode. // // RPC providers put the API key in the URL's path or query string, and the // debug log used to print the whole URL and request body, so turning debug // mode on wrote the key to the console // (https://git.eeqj.de/sneak/AutistMask/issues/410). The log now names the // HTTP method, the URL's origin and the JSON-RPC method, and nothing else of // the request. const { debugFetch, urlOrigin, setRuntimeDebug } = require("../src/shared/log"); const realFetch = globalThis.fetch; afterEach(() => { globalThis.fetch = realFetch; setRuntimeDebug(false); jest.restoreAllMocks(); }); test("logs the origin and JSON-RPC method, not the key in the URL", async () => { setRuntimeDebug(true); const consoleLog = jest.spyOn(console, "log").mockImplementation(() => {}); globalThis.fetch = jest.fn(async () => ({ status: 200 })); await debugFetch( "https://rpc.example.invalid/v3/PATHKEY123?token=QUERYTOKEN456", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ jsonrpc: "2.0", id: 1, method: "eth_chainId", params: [], }), }, ); const logged = consoleLog.mock.calls.flat().join(" "); expect(logged).not.toContain("PATHKEY123"); expect(logged).not.toContain("QUERYTOKEN456"); expect(logged).toContain("https://rpc.example.invalid"); expect(logged).toContain("eth_chainId"); }); test("the origin leaves out a user name and password in the URL", () => { expect( urlOrigin("https://user:SECRETPASS@rpc.example.invalid/v3/KEY"), ).toBe("https://rpc.example.invalid"); expect(urlOrigin("wss://user:SECRETPASS@rpc.example.invalid:8546/")).toBe( "wss://rpc.example.invalid:8546", ); });