Skip to content

Filter the Authorization header for real; release 0.3.1 - #18

Merged
usiegj00 merged 1 commit into
mainfrom
fix-authorization-log-filter
Sep 12, 2026
Merged

usiegj00 merged 1 commit into
mainfrom
fix-authorization-log-filter

Conversation

@usiegj00

Copy link
Copy Markdown
Contributor

Fixes #6.

before:  Authorization: "Basic cm9vdDpTM2NyZXQh"      # base64 of root:S3cret!
after:   Authorization: "Basic [FILTERED]"

The filter expected Authorization: Basic ...; Faraday writes Authorization: "Basic ...", quote before the scheme, so it never matched. The X-Auth-Token and password filtering added with #5 was real, but it never touched this path — @davispuh's report was accurate and still open against main.

Why the tests missed it. The existing spec applied the regex to a sample line I wrote by hand. A pattern that looks right against an invented string can be wrong about the real format. HttpClient now accepts log_device: (default STDOUT) and the new specs drive a real request and assert on what the Faraday logger actually emits — basic credentials, session token and password all absent, while the log stays useful. Restoring the old pattern makes them fail.

Ships as 0.3.1 with #5, which was merged but unreleased. 96 examples, 0 failures.

Reported in #6: verbose output still showed credentials in plaintext.
The pattern expected 'Authorization: Basic ...', but Faraday writes
'Authorization: "Basic ..."' with the quote between the colon and the
scheme, so it never matched and the base64 went to the log intact. The
earlier X-Auth-Token and password work did not touch this path.

Match both the header and headers-hash shapes, and any scheme, keeping
the scheme itself visible since it is useful and not secret.

HttpClient now takes a log_device: (default STDOUT) so the debug log can
be captured, and the new specs assert against what the Faraday logger
really writes. The old unit test checked the regex against a string I
wrote by hand, which is precisely why a filter that never fired looked
correct. With the old pattern restored, the new spec fails.
@usiegj00
usiegj00 merged commit c915073 into main Sep 12, 2026
2 checks passed
@usiegj00
usiegj00 deleted the fix-authorization-log-filter branch September 12, 2026 16:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HttpClient log filtering doesn't work

1 participant