Skip to content

T-1087 Filter Authorization, Proxy-Authorization, Cookie and Set-Cookie headers by default - #22

Draft
PetrHeinz wants to merge 2 commits into
mainfrom
claude/t-1087-filter-authorization
Draft

PetrHeinz wants to merge 2 commits into
mainfrom
claude/t-1087-filter-authorization

Conversation

@PetrHeinz

Copy link
Copy Markdown
Member

The HTTP events middleware logs every request and response header, so a Bearer token or a session cookie sent by a client ends up in Better Stack in clear text unless the app opted into http_header_filters. This makes the middleware filter Authorization, Proxy-Authorization, Cookie and Set-Cookie out of the box, replacing their values with [FILTERED] the same way an explicit filter does.

  • Logtail::Integrations::Rack::HTTPEvents::DEFAULT_HTTP_HEADER_FILTERS holds the default list and is public, so an app can extend it: HTTPEvents.http_header_filters = HTTPEvents::DEFAULT_HTTP_HEADER_FILTERS + ["X-Api-Key"].
  • Setting http_header_filters still replaces the whole list, and an empty list logs every header again.

The first commit only adds the tests and is expected to fail on CI: the default list does not exist yet. The second commit makes them pass. The truffleruby job is red on main already (the logger gem is no longer bundled there).

🤖 Generated with Claude Code

PetrHeinz and others added 2 commits September 23, 2026 16:33
Authorization, Proxy-Authorization, Cookie and Set-Cookie should be
replaced with [FILTERED] without any configuration, and setting
http_header_filters to an empty list should log every header again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ie headers by default

Credential headers were sent to Better Stack in clear text unless the
app configured http_header_filters. DEFAULT_HTTP_HEADER_FILTERS is the
public default list, setting http_header_filters still replaces it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant