Description
Currently we only detect leaks in outgoing server responses.
Im dmno, we also detected leaks in outgoing http requests to other servers (not the client) by patching fetch.
This requires that the user can specify an allow-list for each secret. For example, a stripe key is only allowed to be sent to api.stripe.com
Motivation
No response
Proposed Solution
No response
Alternatives
No response
Additional Information
No response