Skip to content

Keep request URL credentials out of HTTP errors - #10

Merged
Ri-go merged 1 commit into
masterfrom
id-1601-stitch-query-redaction
Sep 18, 2026
Merged

Ri-go merged 1 commit into
masterfrom
id-1601-stitch-query-redaction

Conversation

@Ri-go

@Ri-go Ri-go commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Upstream failures could copy API keys from request URLs into logs and 502 responses. Remove URL credentials, queries and fragments from HTTP error diagnostics while preserving forwarded requests and error classification.

Covers ordinary, hedged and broadcast requests, including wrapped errors and malformed redirects. Tests, race checks, vet and lint pass.

Summary by CodeRabbit

  • Bug Fixes
    • Improved error reporting across request forwarding and RPC handling.
    • Sensitive URL information—including credentials, query parameters, and fragments—is now redacted from error messages and logs.
    • Preserved existing HTTP status codes, error classifications, timeout details, and diagnostic context.
    • Added safeguards for malformed, wrapped, and combined errors to prevent accidental disclosure of sensitive request data.

@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Essentials

Run ID: 97729f4c-731a-40e1-ac33-2e55a760dd4b

📥 Commits

Reviewing files that changed from the base of the PR and between 8a3b3ff and 53f6f18.

📒 Files selected for processing (7)
  • internal/forwarder/broadcast.go
  • internal/forwarder/hedge.go
  • internal/forwarder/http.go
  • internal/forwarder/redaction_test.go
  • internal/log/errors.go
  • internal/log/errors_test.go
  • internal/server/cmt_rpc/server.go
 ____________________________________
< Zero-day? Zero chance on my watch. >
 ------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@linear

linear Bot commented Sep 18, 2026

Copy link
Copy Markdown

ID-1601

@Ri-go
Ri-go marked this pull request as ready for review September 18, 2026 12:29
@Ri-go
Ri-go merged commit 7ce8d4e into master Sep 18, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant