urlSecrets in internal/delivery/target_redact.go treats a target URL's request URI as a secret only when the URL has a path other than /. For a target URL such as https://example.com/?token=… or https://example.com?token=…, the only secret is then the whole URL, so a response that echoes the request line back (POST /?token=… HTTP/1.1) shows the token in the event log and on the event's page. A target URL with a path is not affected.
Found while implementing #312; passing the event's query string on to a target does not change it.
Model: opus-5-5
`urlSecrets` in `internal/delivery/target_redact.go` treats a target URL's request URI as a secret only when the URL has a path other than `/`. For a target URL such as `https://example.com/?token=…` or `https://example.com?token=…`, the only secret is then the whole URL, so a response that echoes the request line back (`POST /?token=… HTTP/1.1`) shows the token in the event log and on the event's page. A target URL with a path is not affected.
Found while implementing https://git.eeqj.de/sneak/webhooker/issues/312; passing the event's query string on to a target does not change it.
Model: opus-5-5
urlSecrets in internal/delivery/target_redact.go also treats the request URI as a secret when the target URL has a query string, whatever its path (empty, / or longer), and the raw query string itself, under the same no-length-floor rule it already applies to paths and userinfo.
A target with "Pass the query string on to this target" on (#312) sends its configured query string followed by & and the event's own; the configured part must still be masked when a response echoes that request line, while the event's part, which the pages already show, need not be.
Tests: a response echoing POST /?token=… HTTP/1.1 and POST ?token=…-style lines for https://example.com/?token=… and https://example.com?token=…, with and without the event's query string appended, shows no token on the event log or the event's page; a target URL with a path is masked as before.
Model: opus-5-5
Plan.
- `urlSecrets` in `internal/delivery/target_redact.go` also treats the request URI as a secret when the target URL has a query string, whatever its path (empty, `/` or longer), and the raw query string itself, under the same no-length-floor rule it already applies to paths and userinfo.
- A target with "Pass the query string on to this target" on (https://git.eeqj.de/sneak/webhooker/issues/312) sends its configured query string followed by `&` and the event's own; the configured part must still be masked when a response echoes that request line, while the event's part, which the pages already show, need not be.
- Tests: a response echoing `POST /?token=… HTTP/1.1` and `POST ?token=…`-style lines for `https://example.com/?token=…` and `https://example.com?token=…`, with and without the event's query string appended, shows no token on the event log or the event's page; a target URL with a path is masked as before.
Model: opus-5-5
#502: urlSecrets now treats a target URL's query string, and the request URI that carries it, as secrets whenever the URL has a query string, whatever its path. So an echoed POST /?token=… HTTP/1.1 is masked for both https://example.com/?token=… and https://example.com?token=…. With the event's query string passed on, only the target's own part is masked. A URL with a path is masked as before.
Judgement call: the query string gets no length floor, so a short one such as v=1 is now masked wherever a response contains it.
Model: opus-5-5
https://git.eeqj.de/sneak/webhooker/pulls/502: `urlSecrets` now treats a target URL's query string, and the request URI that carries it, as secrets whenever the URL has a query string, whatever its path. So an echoed `POST /?token=… HTTP/1.1` is masked for both `https://example.com/?token=…` and `https://example.com?token=…`. With the event's query string passed on, only the target's own part is masked. A URL with a path is masked as before.
Judgement call: the query string gets no length floor, so a short one such as `v=1` is now masked wherever a response contains it.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
urlSecretsininternal/delivery/target_redact.gotreats a target URL's request URI as a secret only when the URL has a path other than/. For a target URL such ashttps://example.com/?token=…orhttps://example.com?token=…, the only secret is then the whole URL, so a response that echoes the request line back (POST /?token=… HTTP/1.1) shows the token in the event log and on the event's page. A target URL with a path is not affected.Found while implementing #312; passing the event's query string on to a target does not change it.
Model: opus-5-5
Plan.
urlSecretsininternal/delivery/target_redact.goalso treats the request URI as a secret when the target URL has a query string, whatever its path (empty,/or longer), and the raw query string itself, under the same no-length-floor rule it already applies to paths and userinfo.&and the event's own; the configured part must still be masked when a response echoes that request line, while the event's part, which the pages already show, need not be.POST /?token=… HTTP/1.1andPOST ?token=…-style lines forhttps://example.com/?token=…andhttps://example.com?token=…, with and without the event's query string appended, shows no token on the event log or the event's page; a target URL with a path is masked as before.Model: opus-5-5
#502:
urlSecretsnow treats a target URL's query string, and the request URI that carries it, as secrets whenever the URL has a query string, whatever its path. So an echoedPOST /?token=… HTTP/1.1is masked for bothhttps://example.com/?token=…andhttps://example.com?token=…. With the event's query string passed on, only the target's own part is masked. A URL with a path is masked as before.Judgement call: the query string gets no length floor, so a short one such as
v=1is now masked wherever a response contains it.Model: opus-5-5