T-3627 Add a redact option that filters sensitive keys from fields and request details - #42
Merged
Merged
Conversation
Pins Rails-style key matching (case-insensitive substring or RegExp), [FILTERED] replacement deep inside fields and request details, and inheritance by child loggers and route handler logs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
LoggerConfig.redact and the route handler config take Rails-style key patterns (case-insensitive substring or RegExp); matching values in the fields and in the request details become [FILTERED]. Off unless set, inherited by child loggers. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A substring pattern "cookie" also matches the "cookies" map, which is the documented Rails-style behaviour; the test wanted only the header. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PetrHeinz
marked this pull request as ready for review
September 29, 2026 10:52
Keeps the retry fields next to redact in LoggerConfig and the renamed LogRequestDetails type next to redact in the route handler config. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There was no built-in way to keep secrets out of the logs: with
logRequestDetailsevery header, cookie and body field went to Better Stack as is, and so did whatever the app put into the log fields.redactoption onLoggerConfig(so onnew Logger(),useLogger()andLogger.middleware) and on thewithBetterStackRouteHandlerconfig: a list of key patterns matched the way Rails'filter_parametersdoes. A string matches any key containing it, case-insensitively; a RegExp is tested against the key. Matching values anywhere in the fields and in the request details are replaced with[FILTERED].req.loginside a wrapped route handler are filtered too.The first commit adds the tests only and is expected to fail CI; the feature follows in the second commit. The third commit corrects one of the new tests: it used the substring pattern
cookie, which by design also matches thecookiesmap, where it meant only the header.🤖 Generated with Claude Code