Repository navigation
fix: mask authorization credentials and signed urls in code variables - #1015
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxaTpjkJ3QxjaCSrYxXFHW
Contributor
posthog-python Compliance ReportDate: 2026-10-06T12:57:56.274120+00:00 ✅ All Tests Passed!121/121 tests passed Capture_V1 Tests✅ 95/95 tests passed View Details
Capture_Ai Tests✅ 5/5 tests passed View Details
Feature_Flags Tests✅ 17/17 tests passed View Details
Feature_Flags_Local_Evaluation Tests✅ 4/4 tests passed View Details
|
Contributor
|
[Medium risk] Adds credential masking to exception reporting. The PR appears safe to merge, though authorization matching can unnecessarily remove diagnostic prose. Reviews (2) · Last reviewed commit: "fix: mask short basic credentials in cod..." |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxaTpjkJ3QxjaCSrYxXFHW
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxaTpjkJ3QxjaCSrYxXFHW
ablaszkiewicz
marked this pull request as ready for review
October 6, 2026 11:30
PR overviewAll previously flagged issues have been addressed. No open security concerns remain on this pull request. Security reviewNo open security issues remain on this pull request. Fixed/addressed: 1 · PR risk: 0/10 |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxaTpjkJ3QxjaCSrYxXFHW
hpouillot
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
💡 Motivation and Context
With code variables on, an HTTP
BearerorBasiccredential reaches error tracking unmasked whenever it is not stored under a header-name key.scope(every FastAPI and Starlette request) holds headers as(name, value)tuples.authorizationmatches theauthpattern and gets redacted. The value next to it stays.sigquery parameter that no rule matches.Changes:
Bearer <credential>andBasic <credential>becomeBearer $$_posthog_redacted_based_on_masking_rules_$$in every string, repr and mapping key the SDK emits. The scheme stays for context.Bearer: <token>.basicConfigstays.Authorizationvalues, soBearer postgresql://user:pass@hostcannot hide the URL from the URL pass.Basiccredential of any length is redacted when it decodes touser:password, soBasic YTpi(a:b) is caught while "basic auth" stays.(?i)[?&]sig=. A baresigwould redact any value that contains "design" or "signal", because mask patterns also match values.posthog.mcp.get_tool_input_properties, which feat(mcp): record safe tool input names #989 added without a snapshot update, somake public_api_checkfails onmainwithout it.💚 How did you test it?
Basiccredential, a lowercase-only token, colon and quote separators, and an Azure SAS URL. All of them fail onmain.basicConfig(level=10),design,signal_handlerand/signup?step=2unchanged.Performance
The new check adds one regex pass to every string and key the masker emits. Only exceptions captured with code variables pay it.
Median time per operation,
main(2273c7a) against this branch (5819111):maincapture_exception, 6 framesbearer/basicwould cost about 50 ns, so it could cut the added cost about 4x. This PR does not include it.Method and script
Apple M4 Pro, macOS 26.7.1, Python 3.14.7. The same interpreter imports each checkout through
PYTHONPATH. Three alternating runs per version, 7 repeats per case each, median per operation. Minimums give the same changes within 3 percentage points.📝 Checklist
If releasing new changes
sampo addto generate a changeset fileThe changeset was written by hand in the
sampo addformat:.sampo/changesets/mask-authorization-credentials.md.🤖 Agent context
Autonomy: Human-driven (agent-assisted)
Claude Code with Claude Opus 5.5 (
claude-opus-5-5). Skills:writing-pr-descriptions.The scope is limited on purpose to
Bearer/Basicandsig. Hex-only keys and Discord webhook URLs also pass the current rules, and stay out of this PR.Credentials are matched by value, not by teaching the list walker about
(name, value)pairs. The value rule also covers neutral locals and reprs, and a pair rule would not.A synthetic harness replayed each shape through released SDK versions with generated fake values. It found these gaps in 7.63.0 and confirmed this branch masks them.
Review round: a local QA pass and the Greptile P1 thread found lowercase-only, separator and short
Basiccredentials passing through. All three are fixed. A second bot round found a pass-order bypass and prose loss. Both are fixed: URLs go first, and lowercase words of up to 15 letters count as prose. Wider signed-URL parameters (X-Amz-Signature,Signature) stay out of scope.🤖 Generated with Claude Code
https://claude.ai/code/session_01MxaTpjkJ3QxjaCSrYxXFHW