A response that echoed the request line for a target URL with a query string but no path (https://example.com/?token=… or https://example.com?token=…) showed the token on the event log and the event's page: urlSecrets treated the request URI as a secret only when the URL had a path other than /.
urlSecrets now treats each of these as a secret on its own: the path, unless it is empty or /; and, whenever the URL has a query string, that query string and the request URI that carries it. A URL with a path is masked as before, and its query string alone now is too. The doc comment says so.
With "Pass the query string on to this target" on (#501), an echoed request line has only the target's own query string masked; the event's part after the & stays visible, as the event's page already shows it.
Judgement call: the query string gets no length floor, like the path and userinfo, so a short one such as v=1 is now masked wherever a response contains it, not only inside the request URI.
Model: opus-5-5
A response that echoed the request line for a target URL with a query string but no path (`https://example.com/?token=…` or `https://example.com?token=…`) showed the token on the event log and the event's page: `urlSecrets` treated the request URI as a secret only when the URL had a path other than `/`.
`urlSecrets` now treats each of these as a secret on its own: the path, unless it is empty or `/`; and, whenever the URL has a query string, that query string and the request URI that carries it. A URL with a path is masked as before, and its query string alone now is too. The doc comment says so.
With "Pass the query string on to this target" on (https://git.eeqj.de/sneak/webhooker/pulls/501), an echoed request line has only the target's own query string masked; the event's part after the `&` stays visible, as the event's page already shows it.
Judgement call: the query string gets no length floor, like the path and userinfo, so a short one such as `v=1` is now masked wherever a response contains it, not only inside the request URI.
Model: opus-5-5
clawbot
self-assigned this 2026-10-04 03:20:18 +02:00
The Redactor treated a target URL's request URI as a secret only when
the URL had a path other than "/", so a response echoing the request
line for https://example.com/?token=... or https://example.com?token=...
showed the token on the event log and the event's page. urlSecrets now
treats the query string, and the request URI that carries it, as
secrets whenever the URL has one, whatever its path. With the event's
query string passed on, only the target's own part is masked.
Model: opus-5-5
Review passed: #502 meets #500 and its plan, rebased onto current next.
Model: opus-5-5
Review passed: https://git.eeqj.de/sneak/webhooker/pulls/502 meets https://git.eeqj.de/sneak/webhooker/issues/500 and its plan, rebased onto current `next`.
Model: opus-5-5
clawbot
merged commit 46fe7baed0 into next2026-10-04 03:31:38 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
A response that echoed the request line for a target URL with a query string but no path (
https://example.com/?token=…orhttps://example.com?token=…) showed the token on the event log and the event's page:urlSecretstreated the request URI as a secret only when the URL had a path other than/.urlSecretsnow treats each of these as a secret on its own: the path, unless it is empty or/; and, whenever the URL has a query string, that query string and the request URI that carries it. A URL with a path is masked as before, and its query string alone now is too. The doc comment says so.With "Pass the query string on to this target" on (#501), an echoed request line has only the target's own query string masked; the event's part after the
&stays visible, as the event's page already shows it.Judgement call: the query string gets no length floor, like the path and userinfo, so a short one such as
v=1is now masked wherever a response contains it, not only inside the request URI.Model: opus-5-5
Review passed: #502 meets #500 and its plan, rebased onto current
next.Model: opus-5-5