Commit 70f126d
committed
Keep the API token out of the errors the client throws
`ApiError` stored the options of the failed query verbatim, so
`error.options.token` held the API token in clear text — and travelled with the
error wherever it went: into `console.error()` output shipped to log
aggregators, into error trackers, and into any HTTP handler that caught it and
echoed it back to its caller. Our own tech starters did the latter, which turned
a 500 into a way to read the token.
The token is now replaced by `[REDACTED, ending in abcd]`, which still tells two
tokens apart while debugging; the real one only ever reaches the `Authorization`
header. For the same reason `query`, `options` and `response` are no longer
enumerable: reading `error.options` explicitly works exactly as before, as the
README documents, but the details of the failed query stop travelling through
`JSON.stringify()`, object spread or `serialize-error` by accident.
Claude-Session: https://claude.ai/code/session_01VQGrgtFYHo3vSXkifJ1bom1 parent f61c569 commit 70f126d
4 files changed
Lines changed: 76 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
260 | 260 | | |
261 | 261 | | |
262 | 262 | | |
263 | | - | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
264 | 266 | | |
265 | 267 | | |
266 | 268 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
20 | 55 | | |
21 | 56 | | |
22 | 57 | | |
| |||
85 | 120 | | |
86 | 121 | | |
87 | 122 | | |
88 | | - | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
89 | 126 | | |
90 | 127 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
51 | | - | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
52 | 69 | | |
53 | 70 | | |
54 | 71 | | |
| |||
0 commit comments