Skip to content

Fix #271: Mask sensitive headers in request logs - #272

Open
samdark wants to merge 1 commit into
masterfrom
fix/271-sensitive-header-logging
Open

samdark wants to merge 1 commit into
masterfrom
fix/271-sensitive-header-logging

Conversation

@samdark

@samdark samdark commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Request logs currently expose authentication headers verbatim. Mask Authorization, Proxy-Authorization, and Cookie values in the shared log/profile token builder used by StreamTransport and CurlTransport, including batch requests.

Adds Client::$sensitiveHeaders for case-insensitive header selection. Applications can extend the list for custom credentials or explicitly use an empty list to restore unmasked logging. Outgoing headers, public method signatures, and content truncation remain unchanged. Documents that debug-panel replay cannot recover masked credentials; URL parameters and request bodies are outside this header-only fix.

Includes regression tests and a 2.0.18 changelog entry. Corrects the existing nullable-content PHPDoc and removes its now-obsolete PHPStan baseline entry; no new suppressions are added.

Fixes #271.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 22:27
@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.19%. Comparing base (4f70d14) to head (86faac9).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@             Coverage Diff              @@
##             master     #272      +/-   ##
============================================
+ Coverage     98.17%   98.19%   +0.01%     
- Complexity      269      272       +3     
============================================
  Files            16       16              
  Lines           769      774       +5     
============================================
+ Hits            755      760       +5     
  Misses           14       14              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The shared implementation correctly covers single and batch transport logging with focused regression tests and documentation.

Review effort: Balanced
Findings: None

What changed in this PR

Adds configurable, case-insensitive masking of sensitive request headers in shared logging and profiling tokens.

Changes:

  • Masks authorization and cookie headers without modifying outgoing requests.
  • Adds regression tests and configuration documentation.
  • Updates PHPDoc, PHPStan baseline, and changelog.
File Description
src/​Client.php Implements configurable header masking.
tests/​ClientTest.php Tests masking, customization, disabling, and immutability.
docs/​guide/​usage-logging.md Documents masking configuration and scope.
docs/​guide/​topics-debug.md Explains replay limitations.
phpstan-baseline.neon Removes obsolete suppression.
CHANGELOG.md Records the fix.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sensitive headers logged in info log

2 participants