Skip to content

Cap Dataverse token-check body read; scrub tokens from create-experiment logs - #283

Open
jodeleeuw wants to merge 1 commit into
testfrom
fix/pr281-token-log-hardening
Open

jodeleeuw wants to merge 1 commit into
testfrom
fix/pr281-token-log-hardening

Conversation

@jodeleeuw

Copy link
Copy Markdown
Member

Two follow-ups from the review of #281 (test → main).

Unbounded body read in validateStaticToken. The non-200 branch read the full response body with response.text() from a server URL the researcher chooses. A hostile or slow-dripping installation could exhaust memory in dashboardapi, which serves ~16 dashboard routes. It now reads at most 4KB for at most 5s, then destroys the stream. The logged body is also flattened to one line so a multi-line block page stays in one log entry.

Token in create-experiment logs. The new console.error logged the raw provider Error. A Dataverse installation can answer "Bad api key ", which would put the API key in Cloud Logging. The logged stack now goes through redactSecret (new functions/src/redact.ts, shared with validateStaticToken), and the network code is kept. The 502 detail sent back to the researcher is unchanged.

Tests

  • providers-dataverse.test.js: endless body is capped and destroyed, stalled body times out, multi-line body is flattened.
  • New create-experiment-log-redaction.test.js: fails on the current test code, passes with the fix.
  • tsc --noEmit passes.

🤖 Generated with Claude Code

…logs

validateStaticToken read the whole non-200 body with response.text() from a
researcher-chosen server, so a hostile or slow-dripping installation could
exhaust dashboardapi's shared memory. It now reads at most 4KB for at most
5s, then drops the connection, and flattens the logged body to one line.

createExperimentHandler logged the raw provider Error, but a Dataverse
installation can echo the API key in its error text. The logged stack is
now scrubbed with the same redaction validateStaticToken uses.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant