Skip to content

v8.5.37 — a credential that follows its name in a route

Choose a tag to compare

@marcing marcing released this 22 Sep 09:23
· 0 commits to main since this release
0cb626d

v8.5.37 - A credential that follows its name in a route

removeFromPath() saw only the SHAPE rule: a segment that looks like a token.
It missed the other half, which a client's UrlScrubber had - a credential named
by the segment in front of it. /token/abc, /api_key/xyz, /reset-password/short:
the value need not look like anything, because the route already said what it
is.

Promoted, and narrowed on the way. The client matched the naming segment
against BOTH its lists, so a path segment called code, key, hash, pin, otp or
sig redacted whatever followed - and /code/at lost its country. Those names
are query-only here for exactly that reason, so this reads the substring list
alone: token, password, secret, jwt, bearer, signature, api_key. A route
segment carrying one of those is naming a credential; the others are ordinary
words in a path.

Pinned in the shared corpus, which grew a paths group carrying both halves -
what the rule catches and what must survive it, /de/pre-und-onboarding/
included.