Skip to content

fix: redact sensitive API error headers - #817

Open
ryanduguid wants to merge 1 commit into
XeroAPI:masterfrom
ryanduguid:fix/redact-api-error-headers
Open

fix: redact sensitive API error headers#817
ryanduguid wants to merge 1 commit into
XeroAPI:masterfrom
ryanduguid:fix/redact-api-error-headers

Conversation

@ryanduguid

Copy link
Copy Markdown

Summary

  • redact credential-bearing request and response headers before they are retained in ApiError
  • preserve safe diagnostic headers such as Accept, request IDs, content type, and rate-limit metadata
  • add regression coverage against the serialized payload constructed by generated API clients

This is intentionally additive to the currently open error-object work (#812 / #816): whichever error representation is adopted should not expose request credentials or response cookies.

Validation

  • npm test -- --runInBand src/test/apiError.spec.ts
  • npm test -- --runInBand
  • npm run build
  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants