Mask a target URL's query string when the URL has no path (closes #500) #502

Merged
clawbot merged 1 commits from issue-500-redact-query-request-line into next 2026-10-04 03:31:38 +02:00
1 Commits
Author SHA1 Message Date
sneak eafb815417 Mask a target URL's query string when the URL has no path (closes #500)
check / check (push) Waiting to run
The Redactor treated a target URL's request URI as a secret only when
the URL had a path other than "/", so a response echoing the request
line for https://example.com/?token=... or https://example.com?token=...
showed the token on the event log and the event's page. urlSecrets now
treats the query string, and the request URI that carries it, as
secrets whenever the URL has one, whatever its path. With the event's
query string passed on, only the target's own part is masked.

Model: opus-5-5
2026-10-04 01:17:19 +00:00