v8.5.34 — the names westbahn redacted and this list did not
The names a client redacted and this list did not
A client's OTEL pipeline keeps its own denylists. Comparing them against this
library's showed drift in both directions — and nothing caught it, because
check-sender-parity.php compares the path rule only. The field- and
query-name lists had diverged unseen.
| name | client denylist | php-library | promoted? |
|---|---|---|---|
jwt, bearer |
substring | — | ✅ → substring list |
otp, pin, hash |
exact | — | ✅ → query-only |
apikey |
exact | already covered by api[_-]?key |
— |
auth |
substring | query-only | stays query-only |
cookie |
— | substring | (client lacks it) |
sess |
substring | — | ❌ deliberately not |
email |
substring | masked by value, everywhere | — |
Why the query-only half is query-only
Because that is what the client had them as: its DENYLIST_EXACT matches a
whole name, where its substring list holds password/token/secret. As
field names they over-redact, and this codebase has scar tissue on exactly
that:
hasheatscontent_hashandfilehash— the very content hashes the
asset carve-out exists to keep. A bundle named<group>_<md5>.<mtime>.js
once came back as[redacted]and 273 browser errors could not say which
file threw.pineatsshipping,mapping,spinner,pinnedandzipping—
the same mistakepassonce made withpassengers,compassandbypass.
As a query parameter they are nearly always credentials, so that is where they
now bite.
Why sess is not promoted
The console stores session_id as a first-class column and correlates by it —
it is in the error detail, the issue facets and the grid. Redacting that name
would blind its own session view. The client can keep it locally; it should
not become everyone's default.
Pinned, and applied everywhere
The shared corpus (scrub-body.json in the console repo) grew a urls group
for the query-only half, and the same promotion landed in the console's
Scrubber, the WordPress Redactor and both JS clients in one pass. A list
change obligates every sender — which is what the corpus is for.
Verified: console 39/39 plus its full suite, WordPress 22/22, node 23/23 plus
the 645-test JS suite, php-library Logger 21/21, parity green across five
senders.
Also in this release
Rollup::routeName() gained an optional trailing $module (v8.5.33), and
a client now delegates its four rollup primitives — isStream,
routeName, bucketFor, hostName, plus DURATION_BOUNDS and
DURATION_BUCKETS — rather than carrying character-identical copies. Its own
codeception suite passes unchanged, 8 tests / 50 assertions.
Upgrading
Additive. Two more substring names and three more query-parameter names are
redacted than before; nothing that was redacted stops being.