fix(telemetry): redact credentials from CLI diagnostics - #1640
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
1 Skipped Deployment
|
BYK
pushed a commit
that referenced
this pull request
Sep 28, 2026
## Summary Malformed bearer credentials can be echoed by runtime header-validation errors. Normalize access tokens and reject invalid formatting before constructing authenticated API, Docs, init, and artifact-download requests. Failures use a fixed `AUTH_INVALID` message without the credential and preserve exit code 12. Share one helper for trimming surrounding whitespace and ASCII controls. Internal whitespace, controls, and non-ASCII characters remain invalid; split lines are never joined. Environment selection, token host claims, and cache `Vary` metadata use the same trimming rules. Cache metadata only trims a candidate: validation waits until OAuth refresh and credential selection determine the token actually used. Validate access tokens before SQLite writes, including refreshed credentials. Reject a malformed explicit `auth login --token` before changing the host or clearing existing authentication. Legacy JSON migration skips malformed auth, migrates other settings, and retains the original file with a fixed recovery warning, so help, login, and logout remain usable. Malformed-token failures remain visible as safe `MalformedAuthTokenError` events without retaining the credential or original cause. They do not trigger auto-login or mark a session crashed; ordinary authentication failures keep their existing reporting policy. ## Validation - Full validation at `e754fb328`: 467 unit files, 10,050 passed / 14 skipped (`TZ=UTC`); 34 bundled E2E passed across auth, library, and migration; lint, TypeScript, and bundle build passed. - After test-only cleanup: all 102 affected unit tests and 14 auth E2E passed, along with Biome and `git diff --check`. Production code is unchanged; the full suite and build were not repeated locally. - Property and regression coverage for edge padding, internal invalid characters, auth precedence, OAuth refresh, cache metadata, and persistence. ## Separate work General output and telemetry redaction remains in #1640. SDK invocation isolation (#1645) and rc tokens truncated when copied into `process.env` (#1646) are separate fixes; this PR does not address those earlier input/lifecycle boundaries. Bundler consumers pinned to `sentry ^0.44.0` need a `0.44.x` backport or a dependency update after release.
betegon
force-pushed
the
bt/redact-cli-diagnostics
branch
from
September 29, 2026 05:44
fbf302a to
c060c54
Compare
Contributor
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit c060c54. Configure here.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Runtime errors can echo credentials into command diagnostics. Redact recognizable Sentry tokens and Bearer values in CLI/Stricli errors, SDK errors, and outgoing telemetry envelopes, including credentials split by control characters or escaped in JSON.
Telemetry redaction runs at the final transport boundary, after scope attributes and internal errors are resolved. A detached JSON copy preserves SDK serialization behavior without mutating caller objects or live SDK state. Text redaction has no SDK dependencies, preserving the completion startup path. Fatal diagnostics retain error names while redacting credentials.
This complements the merged auth validation in #1638: diagnostics can still contain credentials from custom headers and other error paths.
Validation
TZ=UTC).Limits
Redaction recognizes Sentry token prefixes and Bearer context; it does not detect arbitrary opaque secrets without that context. Binary attachment bytes are preserved. Successful API response formatting is unchanged.
Runtime header errors can contain ambiguous delimiters inside the credential itself. Redaction conservatively uses the final matching delimiter, which can also hide intervening text when multiple diagnostics are concatenated into one string.