Repository navigation
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #272 +/- ##
============================================
+ Coverage 98.17% 98.19% +0.01%
- Complexity 269 272 +3
============================================
Files 16 16
Lines 769 774 +5
============================================
+ Hits 755 760 +5
Misses 14 14 ☔ View full report in Codecov by Harness. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The shared implementation correctly covers single and batch transport logging with focused regression tests and documentation.
Review effort: Balanced
Findings: None
What changed in this PR
Adds configurable, case-insensitive masking of sensitive request headers in shared logging and profiling tokens.
Changes:
- Masks authorization and cookie headers without modifying outgoing requests.
- Adds regression tests and configuration documentation.
- Updates PHPDoc, PHPStan baseline, and changelog.
| File | Description |
|---|---|
src/Client.php |
Implements configurable header masking. |
tests/ClientTest.php |
Tests masking, customization, disabling, and immutability. |
docs/guide/usage-logging.md |
Documents masking configuration and scope. |
docs/guide/topics-debug.md |
Explains replay limitations. |
phpstan-baseline.neon |
Removes obsolete suppression. |
CHANGELOG.md |
Records the fix. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Request logs currently expose authentication headers verbatim. Mask
Authorization,Proxy-Authorization, andCookievalues in the shared log/profile token builder used by StreamTransport and CurlTransport, including batch requests.Adds
Client::$sensitiveHeadersfor case-insensitive header selection. Applications can extend the list for custom credentials or explicitly use an empty list to restore unmasked logging. Outgoing headers, public method signatures, and content truncation remain unchanged. Documents that debug-panel replay cannot recover masked credentials; URL parameters and request bodies are outside this header-only fix.Includes regression tests and a 2.0.18 changelog entry. Corrects the existing nullable-content PHPDoc and removes its now-obsolete PHPStan baseline entry; no new suppressions are added.
Fixes #271.