Skip to content

fix(notifier): avoid logging websocket error payloads - #102

Open
olavurellefsen wants to merge 1 commit into
mainfrom
fix/notifier-error-log-scrub
Open

olavurellefsen wants to merge 1 commit into
mainfrom
fix/notifier-error-log-scrub

Conversation

@olavurellefsen

@olavurellefsen olavurellefsen commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

  • Replace the Data Pump notification-stream error log with a fixed diagnostic.
  • Do not forward the WebSocket ErrorEvent object or its message to the logger.
  • Add a regression using a synthetic credentialed URL to verify that neither the event payload nor fake secret appears in captured log arguments.

Verification

  • Local bun test: 123 passed; lint and format check passed.
  • GitHub build and integration-test checks passed.

Compatibility

The tenant API and SDK transport/logging changes are separate PRs. This change protects Data Pump logs during their rollout and when older SDK versions emit URL-bearing errors.


Human review context

This PR is part of the Flowcore API-key remediation review brief. Please use the brief for the cross-repository review order and design questions. Code review is requested now; merge, deployment, monitor activation, and credential rotation remain separate gates.

@olavurellefsen
olavurellefsen marked this pull request as ready for review September 29, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant