fix(security): add short-lived payment tokens, referrer policy, and log sanitization - #786
Open
omosvico wants to merge 2 commits into
Open
fix(security): add short-lived payment tokens, referrer policy, and log sanitization#786omosvico wants to merge 2 commits into
omosvico wants to merge 2 commits into
Conversation
…og sanitization Implements Pulsefy#770 - Security: payment tokens in links/deeplinks may leak via referrers or logs - Add payment_link_tokens DB table with short-lived, revocable tokens - PaymentTokenService: generate, validate, rotate, consume, revoke tokens - PaymentTokenController: REST API for token lifecycle management - LinksService now generates tokens alongside canonical params - BulkPaymentLinksService uses tokens in generated URLs - Add Referrer-Policy: no-referrer, X-Content-Type-Options, HSTS to middleware - Add referrer meta tag to payment pages - Sanitize console.log in PaymentPageClient (remove payment data from logs) - Sanitize notification-routing.ts payload logs - Sanitize backend error logs (remove run IDs, link IDs from log messages) - Token expiry sweep integrated into existing cron job
|
@omosvico Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes #770 - Security: payment tokens in links/deeplinks may leak via referrers or logs
Changes
Token-based payment links:
payment_link_tokensDB table for short-lived, revocable tokensPaymentTokenServicewith generate, validate, rotate, consume, revokePaymentTokenControllerwith REST API (POST /payment-tokens/generate,GET /payment-tokens/resolve/:token,POST /payment-tokens/consume/:token,POST /payment-tokens/revoke/:token,POST /payment-tokens/rotate/:token)LinksService.generateMetadata()now generates tokens alongside canonical paramsBulkPaymentLinksServiceuses tokens in generated URLs instead of raw query paramsReferrer leakage prevention:
Referrer-Policy: no-referrerheader added to all frontend responses via middlewareX-Content-Type-Options: nosniffandStrict-Transport-Securityheaders added<meta name="referrer" content="no-referrer">added to payment page metadataLog sanitization:
PaymentPageClient.tsx: removed payment data (amount, asset, username, txHash) fromconsole.loganalytics trackingnotification-routing.ts: removed payload details from warning logs