check / check (push) Successful in 5m28s
The Redactor treated a target URL's request URI as a secret only when the URL had a path other than "/", so a response echoing the request line for https://example.com/?token=... or https://example.com?token=... showed the token on the event log and the event's page. urlSecrets now treats the query string, and the request URI that carries it, as secrets whenever the URL has one, whatever its path. With the event's query string passed on, only the target's own part is masked. Model: opus-5-5