Skip to content

v8.5.35 — sess and signature, so a plain Logger covers westbahn outright

Choose a tag to compare

@marcing marcing released this 22 Sep 09:00
· 36 commits to main since this release
cbac427

sess and signature — a plain Logger now covers a client outright

Two more names off a client's OTEL denylists, and a correction: the first pass
left sess out for a reason that did not hold.

The correction

sess was rejected on the grounds that it would redact session_id, which the
console stores as a first-class column and correlates by. It would not.
queryNames is matched against a query parameter name only, inside
removeFromUrl() — never against a field in a bag. So ?sess=abc is redacted
and the column is untouched.

signature moves from the exact query list to the substring list, where
the client had it: no ordinary field name contains the word, and the exact form
missed webhook_signature and x_signature.

Where that leaves the two lists

client denylist name answered by php-library
key, code, sig, otp, pin, hash, sess query list
api_key, apikey ~api[_-]?key~i
password, passwd, pwd, token, secret substring list
jwt, bearer, signature substring list
auth query-only on purpose — as a substring it eats author, authors, authored_by
email masked by value, domain kept, wherever it appears

Every name is covered. The last two rows are the places the two implementations
genuinely differ, and in both php-library is the better of them: the client's
current auth substring over-redacts ?author=, and its email rule redacts a
whole field only when the name says email, where masking by value catches an
address in ?contact= or ?to= as well and keeps the domain, which is
diagnostic.

Why now

The client's console-client branch is not merged yet. Settling this before
it lands means the divergence never reaches master, and its UrlScrubber can
delegate to a plain new Logger with no addRemove() or addQueryNames()
extras at all.

Verification

Applied in the same pass to the console Scrubber, the WordPress Redactor
and both JS clients, and pinned in the shared corpus (scrub-body.json, whose
urls group drives the query-only half). Console full suite green, WordPress
22/22, node 23/23, the 645-test JS suite green, Logger 21/21, parity green
across five senders.

Upgrading

Additive. One more substring name and one more query name are redacted than
before; nothing that was redacted stops being.