Conversation
Authorization, Proxy-Authorization, Cookie and Set-Cookie should be replaced with [FILTERED] without any configuration, and setting http_header_filters to an empty list should log every header again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ie headers by default Credential headers were sent to Better Stack in clear text unless the app configured http_header_filters. DEFAULT_HTTP_HEADER_FILTERS is the public default list, setting http_header_filters still replaces it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The HTTP events middleware logs every request and response header, so a
Bearertoken or a session cookie sent by a client ends up in Better Stack in clear text unless the app opted intohttp_header_filters. This makes the middleware filterAuthorization,Proxy-Authorization,CookieandSet-Cookieout of the box, replacing their values with[FILTERED]the same way an explicit filter does.Logtail::Integrations::Rack::HTTPEvents::DEFAULT_HTTP_HEADER_FILTERSholds the default list and is public, so an app can extend it:HTTPEvents.http_header_filters = HTTPEvents::DEFAULT_HTTP_HEADER_FILTERS + ["X-Api-Key"].http_header_filtersstill replaces the whole list, and an empty list logs every header again.The first commit only adds the tests and is expected to fail on CI: the default list does not exist yet. The second commit makes them pass. The
trufflerubyjob is red onmainalready (theloggergem is no longer bundled there).🤖 Generated with Claude Code