Filter the Authorization header for real; release 0.3.1 - #18
Merged
Merged
Conversation
Reported in #6: verbose output still showed credentials in plaintext. The pattern expected 'Authorization: Basic ...', but Faraday writes 'Authorization: "Basic ..."' with the quote between the colon and the scheme, so it never matched and the base64 went to the log intact. The earlier X-Auth-Token and password work did not touch this path. Match both the header and headers-hash shapes, and any scheme, keeping the scheme itself visible since it is useful and not secret. HttpClient now takes a log_device: (default STDOUT) so the debug log can be captured, and the new specs assert against what the Faraday logger really writes. The old unit test checked the regex against a string I wrote by hand, which is precisely why a filter that never fired looked correct. With the old pattern restored, the new spec fails.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #6.
The filter expected
Authorization: Basic ...; Faraday writesAuthorization: "Basic ...", quote before the scheme, so it never matched. The X-Auth-Token and password filtering added with #5 was real, but it never touched this path — @davispuh's report was accurate and still open against main.Why the tests missed it. The existing spec applied the regex to a sample line I wrote by hand. A pattern that looks right against an invented string can be wrong about the real format.
HttpClientnow acceptslog_device:(defaultSTDOUT) and the new specs drive a real request and assert on what the Faraday logger actually emits — basic credentials, session token and password all absent, while the log stays useful. Restoring the old pattern makes them fail.Ships as 0.3.1 with #5, which was merged but unreleased. 96 examples, 0 failures.