URLs with userinfo (https://user:pass@host) and Authorization values
other than Bearer (Basic, Digest, Token, and any known scheme after an
Authorization or Proxy-Authorization header name) reached the panel and
agents in clear text. A new credential-redact module masks them, and the
shared helpers (forms-privacy redactMessage, router redactText and the
Analog server log) call it, so serialize, HTTP calls, router URLs, NgRx,
forms and Analog all get the same masking. The URL user stays visible.
Basic only matches base64 that decodes to user:password, Token needs an
opaque value with letters and digits, and Digest needs its parameter
list, so words like "Basic plan" or "Token expired" stay readable.
Secret key names also cover bearer (as a whole name), authHeader,
authKey, authCode and basicAuth. "auth" alone is left out so an auth
state slice stays readable, and author or authorName are not masked.
What and why
URLs with a password (
https://user:pass@host) and Authorization values other than Bearer (Basic,Digest,Token, and any known scheme after anAuthorization:header name) reached the panel and agents in clear text. A newcredential-redact.tsmasks them, and every shared redaction helper calls it (forms-privacyredactMessage, routerredactText, the Analog server log). Soserialize, HTTP calls, router URLs, NgRx, forms and Analog get the same masking. The URL user stays visible. Basic only matches base64 ofuser:password, Token needs an opaque value with letters and digits, and Digest needs its parameter list, so "Basic plan" or "Token expired" stay readable.Secret key names also cover
bearer(whole name),authHeader,authKey,authCodeandbasicAuth.authalone stays visible so auth state slices are readable, andauthor/authorNameare not masked.How it was verified
credential-redaction.test.ts(9 tests; 5 fail with the masking switched off)pnpm test:devtools(1517 passed)pnpm test:panel(242 passed)pnpm typecheckpnpm format:checkpnpm docs:buildpnpm commit:checkScreenshots
None attached.
Notes for reviewers
beareris matched as a whole key only. Making it a secret word would also mask values under keys that are bearer tokens themselves, whichredaction-leaks.test.tskeeps visible.https://ghp_x@github.com), and a password inside a percent-encoded return URL.Generated by Claude Code
Summary by CodeRabbit
authHeader,authKey,authCode, andbasicAuth, are now recognized for masking. A key named onlyauthis not treated as secret.