Skip to content

T-3627 Add a redact option that filters sensitive keys from fields and request details - #42

Merged
PetrHeinz merged 4 commits into
mainfrom
claude/t-3627-redact
Sep 29, 2026
Merged

PetrHeinz merged 4 commits into
mainfrom
claude/t-3627-redact

Conversation

@PetrHeinz

@PetrHeinz PetrHeinz commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

There was no built-in way to keep secrets out of the logs: with logRequestDetails every header, cookie and body field went to Better Stack as is, and so did whatever the app put into the log fields.

  • New redact option on LoggerConfig (so on new Logger(), useLogger() and Logger.middleware) and on the withBetterStackRouteHandler config: a list of key patterns matched the way Rails' filter_parameters does. A string matches any key containing it, case-insensitively; a RegExp is tested against the key. Matching values anywhere in the fields and in the request details are replaced with [FILTERED].
  • Nothing is redacted unless the option is set, so existing setups are unchanged. Child loggers inherit the option, so logs written through req.log inside a wrapped route handler are filtered too.

The first commit adds the tests only and is expected to fail CI; the feature follows in the second commit. The third commit corrects one of the new tests: it used the substring pattern cookie, which by design also matches the cookies map, where it meant only the header.

🤖 Generated with Claude Code

PetrHeinz and others added 3 commits September 23, 2026 16:26
Pins Rails-style key matching (case-insensitive substring or RegExp),
[FILTERED] replacement deep inside fields and request details, and
inheritance by child loggers and route handler logs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
LoggerConfig.redact and the route handler config take Rails-style key
patterns (case-insensitive substring or RegExp); matching values in the
fields and in the request details become [FILTERED]. Off unless set,
inherited by child loggers.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A substring pattern "cookie" also matches the "cookies" map, which is
the documented Rails-style behaviour; the test wanted only the header.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PetrHeinz
PetrHeinz marked this pull request as ready for review September 29, 2026 10:52
Keeps the retry fields next to redact in LoggerConfig and the renamed
LogRequestDetails type next to redact in the route handler config.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PetrHeinz
PetrHeinz merged commit 9f05d17 into main Sep 29, 2026
47 of 48 checks passed
@PetrHeinz
PetrHeinz deleted the claude/t-3627-redact branch September 29, 2026 17:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant