Mask a target URL's query string when the URL has no path (closes #500) #502

Merged
clawbot merged 1 commits from issue-500-redact-query-request-line into next 2026-10-04 03:31:38 +02:00
Collaborator

A response that echoed the request line for a target URL with a query string but no path (https://example.com/?token=… or https://example.com?token=…) showed the token on the event log and the event's page: urlSecrets treated the request URI as a secret only when the URL had a path other than /.

urlSecrets now treats each of these as a secret on its own: the path, unless it is empty or /; and, whenever the URL has a query string, that query string and the request URI that carries it. A URL with a path is masked as before, and its query string alone now is too. The doc comment says so.

With "Pass the query string on to this target" on (#501), an echoed request line has only the target's own query string masked; the event's part after the & stays visible, as the event's page already shows it.

Judgement call: the query string gets no length floor, like the path and userinfo, so a short one such as v=1 is now masked wherever a response contains it, not only inside the request URI.

Model: opus-5-5

A response that echoed the request line for a target URL with a query string but no path (`https://example.com/?token=…` or `https://example.com?token=…`) showed the token on the event log and the event's page: `urlSecrets` treated the request URI as a secret only when the URL had a path other than `/`. `urlSecrets` now treats each of these as a secret on its own: the path, unless it is empty or `/`; and, whenever the URL has a query string, that query string and the request URI that carries it. A URL with a path is masked as before, and its query string alone now is too. The doc comment says so. With "Pass the query string on to this target" on (https://git.eeqj.de/sneak/webhooker/pulls/501), an echoed request line has only the target's own query string masked; the event's part after the `&` stays visible, as the event's page already shows it. Judgement call: the query string gets no length floor, like the path and userinfo, so a short one such as `v=1` is now masked wherever a response contains it, not only inside the request URI. Model: opus-5-5
clawbot self-assigned this 2026-10-04 03:20:18 +02:00
clawbot added 1 commit 2026-10-04 03:20:18 +02:00
The Redactor treated a target URL's request URI as a secret only when
the URL had a path other than "/", so a response echoing the request
line for https://example.com/?token=... or https://example.com?token=...
showed the token on the event log and the event's page. urlSecrets now
treats the query string, and the request URI that carries it, as
secrets whenever the URL has one, whatever its path. With the event's
query string passed on, only the target's own part is masked.

Model: opus-5-5
clawbot added the needs-review label 2026-10-04 03:20:23 +02:00
Author
Collaborator

Review passed: #502 meets #500 and its plan, rebased onto current next.

Model: opus-5-5

Review passed: https://git.eeqj.de/sneak/webhooker/pulls/502 meets https://git.eeqj.de/sneak/webhooker/issues/500 and its plan, rebased onto current `next`. Model: opus-5-5
clawbot merged commit 46fe7baed0 into next 2026-10-04 03:31:38 +02:00
clawbot deleted branch issue-500-redact-query-request-line 2026-10-04 03:31:39 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#502