v8.5.37 — a credential that follows its name in a route
v8.5.37 - A credential that follows its name in a route
removeFromPath() saw only the SHAPE rule: a segment that looks like a token.
It missed the other half, which a client's UrlScrubber had - a credential named
by the segment in front of it. /token/abc, /api_key/xyz, /reset-password/short:
the value need not look like anything, because the route already said what it
is.
Promoted, and narrowed on the way. The client matched the naming segment
against BOTH its lists, so a path segment called code, key, hash, pin, otp or
sig redacted whatever followed - and /code/at lost its country. Those names
are query-only here for exactly that reason, so this reads the substring list
alone: token, password, secret, jwt, bearer, signature, api_key. A route
segment carrying one of those is naming a credential; the others are ordinary
words in a path.
Pinned in the shared corpus, which grew a paths group carrying both halves -
what the rule catches and what must survive it, /de/pre-und-onboarding/
included.