Skip to content

v8.5.34 — the names westbahn redacted and this list did not

Choose a tag to compare

@marcing marcing released this 22 Sep 08:21
· 0 commits to main since this release
f7856c9

The names a client redacted and this list did not

A client's OTEL pipeline keeps its own denylists. Comparing them against this
library's showed drift in both directions — and nothing caught it, because
check-sender-parity.php compares the path rule only. The field- and
query-name lists had diverged unseen.

name client denylist php-library promoted?
jwt, bearer substring — ✅ → substring list
otp, pin, hash exact — ✅ → query-only
apikey exact already covered by api[_-]?key —
auth substring query-only stays query-only
cookie — substring (client lacks it)
sess substring — ❌ deliberately not
email substring masked by value, everywhere —

Why the query-only half is query-only

Because that is what the client had them as: its DENYLIST_EXACT matches a
whole name, where its substring list holds password/token/secret. As
field names they over-redact, and this codebase has scar tissue on exactly
that:

  • hash eats content_hash and filehash — the very content hashes the
    asset carve-out exists to keep. A bundle named <group>_<md5>.<mtime>.js
    once came back as [redacted] and 273 browser errors could not say which
    file threw.
  • pin eats shipping, mapping, spinner, pinned and zipping —
    the same mistake pass once made with passengers, compass and bypass.

As a query parameter they are nearly always credentials, so that is where they
now bite.

Why sess is not promoted

The console stores session_id as a first-class column and correlates by it —
it is in the error detail, the issue facets and the grid. Redacting that name
would blind its own session view. The client can keep it locally; it should
not become everyone's default.

Pinned, and applied everywhere

The shared corpus (scrub-body.json in the console repo) grew a urls group
for the query-only half, and the same promotion landed in the console's
Scrubber, the WordPress Redactor and both JS clients in one pass. A list
change obligates every sender — which is what the corpus is for.

Verified: console 39/39 plus its full suite, WordPress 22/22, node 23/23 plus
the 645-test JS suite, php-library Logger 21/21, parity green across five
senders.

Also in this release

Rollup::routeName() gained an optional trailing $module (v8.5.33), and
a client now delegates its four rollup primitives — isStream,
routeName, bucketFor, hostName, plus DURATION_BOUNDS and
DURATION_BUCKETS — rather than carrying character-identical copies. Its own
codeception suite passes unchanged, 8 tests / 50 assertions.

Upgrading

Additive. Two more substring names and three more query-parameter names are
redacted than before; nothing that was redacted stops being.