The Redactor misses an echoed request line when the target URL has a query string but no path #500

Closed
opened 2026-10-04 02:15:36 +02:00 by clawbot · 2 comments
Collaborator

urlSecrets in internal/delivery/target_redact.go treats a target URL's request URI as a secret only when the URL has a path other than /. For a target URL such as https://example.com/?token=… or https://example.com?token=…, the only secret is then the whole URL, so a response that echoes the request line back (POST /?token=… HTTP/1.1) shows the token in the event log and on the event's page. A target URL with a path is not affected.

Found while implementing #312; passing the event's query string on to a target does not change it.

Model: opus-5-5

`urlSecrets` in `internal/delivery/target_redact.go` treats a target URL's request URI as a secret only when the URL has a path other than `/`. For a target URL such as `https://example.com/?token=…` or `https://example.com?token=…`, the only secret is then the whole URL, so a response that echoes the request line back (`POST /?token=… HTTP/1.1`) shows the token in the event log and on the event's page. A target URL with a path is not affected. Found while implementing https://git.eeqj.de/sneak/webhooker/issues/312; passing the event's query string on to a target does not change it. Model: opus-5-5
clawbot self-assigned this 2026-10-04 02:23:19 +02:00
Author
Collaborator

Plan.

  • urlSecrets in internal/delivery/target_redact.go also treats the request URI as a secret when the target URL has a query string, whatever its path (empty, / or longer), and the raw query string itself, under the same no-length-floor rule it already applies to paths and userinfo.
  • A target with "Pass the query string on to this target" on (#312) sends its configured query string followed by & and the event's own; the configured part must still be masked when a response echoes that request line, while the event's part, which the pages already show, need not be.
  • Tests: a response echoing POST /?token=… HTTP/1.1 and POST ?token=…-style lines for https://example.com/?token=… and https://example.com?token=…, with and without the event's query string appended, shows no token on the event log or the event's page; a target URL with a path is masked as before.

Model: opus-5-5

Plan. - `urlSecrets` in `internal/delivery/target_redact.go` also treats the request URI as a secret when the target URL has a query string, whatever its path (empty, `/` or longer), and the raw query string itself, under the same no-length-floor rule it already applies to paths and userinfo. - A target with "Pass the query string on to this target" on (https://git.eeqj.de/sneak/webhooker/issues/312) sends its configured query string followed by `&` and the event's own; the configured part must still be masked when a response echoes that request line, while the event's part, which the pages already show, need not be. - Tests: a response echoing `POST /?token=… HTTP/1.1` and `POST ?token=…`-style lines for `https://example.com/?token=…` and `https://example.com?token=…`, with and without the event's query string appended, shows no token on the event log or the event's page; a target URL with a path is masked as before. Model: opus-5-5
Author
Collaborator

#502: urlSecrets now treats a target URL's query string, and the request URI that carries it, as secrets whenever the URL has a query string, whatever its path. So an echoed POST /?token=… HTTP/1.1 is masked for both https://example.com/?token=… and https://example.com?token=…. With the event's query string passed on, only the target's own part is masked. A URL with a path is masked as before.

Judgement call: the query string gets no length floor, so a short one such as v=1 is now masked wherever a response contains it.

Model: opus-5-5

https://git.eeqj.de/sneak/webhooker/pulls/502: `urlSecrets` now treats a target URL's query string, and the request URI that carries it, as secrets whenever the URL has a query string, whatever its path. So an echoed `POST /?token=… HTTP/1.1` is masked for both `https://example.com/?token=…` and `https://example.com?token=…`. With the event's query string passed on, only the target's own part is masked. A URL with a path is masked as before. Judgement call: the query string gets no length floor, so a short one such as `v=1` is now masked wherever a response contains it. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#500