Conversation
…logs validateStaticToken read the whole non-200 body with response.text() from a researcher-chosen server, so a hostile or slow-dripping installation could exhaust dashboardapi's shared memory. It now reads at most 4KB for at most 5s, then drops the connection, and flattens the logged body to one line. createExperimentHandler logged the raw provider Error, but a Dataverse installation can echo the API key in its error text. The logged stack is now scrubbed with the same redaction validateStaticToken uses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two follow-ups from the review of #281 (test → main).
Unbounded body read in
validateStaticToken. The non-200 branch read the full response body withresponse.text()from a server URL the researcher chooses. A hostile or slow-dripping installation could exhaust memory indashboardapi, which serves ~16 dashboard routes. It now reads at most 4KB for at most 5s, then destroys the stream. The logged body is also flattened to one line so a multi-line block page stays in one log entry.Token in create-experiment logs. The new
console.errorlogged the raw providerError. A Dataverse installation can answer "Bad api key ", which would put the API key in Cloud Logging. The logged stack now goes throughredactSecret(newfunctions/src/redact.ts, shared withvalidateStaticToken), and the networkcodeis kept. The 502 detail sent back to the researcher is unchanged.Tests
providers-dataverse.test.js: endless body is capped and destroyed, stalled body times out, multi-line body is flattened.create-experiment-log-redaction.test.js: fails on the currenttestcode, passes with the fix.tsc --noEmitpasses.🤖 Generated with Claude Code