fix: redact Authorization header in request timeout error cause - #2229
Conversation
The timeout error embedded the full RequestInit (including 'Authorization: Bearer <apiKey>') in error.cause, leaking the API key to logs and error trackers. Store a copy with Authorization redacted.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 4 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe timeout error now stores a sanitized request cause. Tests verify API-key redaction, retained request metadata, and unauthenticated behavior. ChangesTimeout Error Redaction
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to Timeout errors now retain useful request diagnostics while redacting Authorization values, with coverage for authenticated, metadata-preservation, and unauthenticated cases. The change is ready to merge. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
A rabbit reads each line, Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2229 +/- ##
==========================================
+ Coverage 98.11% 98.14% +0.03%
==========================================
Files 14 14
Lines 688 700 +12
Branches 109 110 +1
==========================================
+ Hits 675 687 +12
Misses 12 12
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Keep error tests next to the other error-class coverage and exercise the constructor directly instead of a hanging fetch.
Request timeouts embedded the full
RequestInit— includingAuthorization: Bearer <key>— inerror.cause, leaking the API key into logs and error trackers. This change stores a copy with theAuthorizationheader redacted, keeping timeout/method/headers for debugging. Addstests/request-timeout-redaction.test.ts(3 tests, green).Summary by CodeRabbit