Files
EpicNext-Cms/src/lib/sentry-redact.ts
T
openhands 17847545dd
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s
Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
2026-07-26 20:28:11 +02:00

53 lines
1.6 KiB
TypeScript

import type { ErrorEvent, EventHint } from "@sentry/nextjs";
const SENSITIVE_KEY_RE =
/password|secret|token|otp|recovery|authTicket|two_factor|api_key/i;
const REDACTED = "[Redacted]";
function redactObject(input: unknown, depth = 0): unknown {
if (depth > 4 || input == null) return input;
if (Array.isArray(input)) return input.map((v) => redactObject(v, depth + 1));
if (typeof input !== "object") return input;
const out: Record<string, unknown> = {};
for (const [key, value] of Object.entries(input as Record<string, unknown>)) {
if (SENSITIVE_KEY_RE.test(key)) {
out[key] = REDACTED;
} else {
out[key] = redactObject(value, depth + 1);
}
}
return out;
}
/** Scrub cookies/auth headers and sensitive keys before sending to Sentry. */
export function redactSentryEvent(
event: ErrorEvent,
_hint: EventHint,
): ErrorEvent | null {
if (event.request) {
if (event.request.cookies) {
event.request.cookies =
REDACTED as unknown as typeof event.request.cookies;
}
if (event.request.headers) {
const headers = event.request.headers as Record<string, string>;
if (headers.cookie) headers.cookie = REDACTED;
if (headers.Cookie) headers.Cookie = REDACTED;
if (headers.authorization) headers.authorization = REDACTED;
if (headers.Authorization) headers.Authorization = REDACTED;
}
if (event.request.data) {
event.request.data = redactObject(
event.request.data,
) as typeof event.request.data;
}
}
if (event.extra)
event.extra = redactObject(event.extra) as typeof event.extra;
if (event.contexts) {
event.contexts = redactObject(event.contexts) as typeof event.contexts;
}
return event;
}