- Remove .prettierrc (dead config, Biome replaces Prettier) - Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat - Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit - Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts - Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars - Replace barrel export src/types/index.ts with direct @/types/common imports - Make trustHost conditional (development only) in auth.ts - Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations - Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
53 lines
1.6 KiB
TypeScript
53 lines
1.6 KiB
TypeScript
import type { ErrorEvent, EventHint } from "@sentry/nextjs";
|
|
|
|
const SENSITIVE_KEY_RE =
|
|
/password|secret|token|otp|recovery|authTicket|two_factor|api_key/i;
|
|
const REDACTED = "[Redacted]";
|
|
|
|
function redactObject(input: unknown, depth = 0): unknown {
|
|
if (depth > 4 || input == null) return input;
|
|
if (Array.isArray(input)) return input.map((v) => redactObject(v, depth + 1));
|
|
if (typeof input !== "object") return input;
|
|
|
|
const out: Record<string, unknown> = {};
|
|
for (const [key, value] of Object.entries(input as Record<string, unknown>)) {
|
|
if (SENSITIVE_KEY_RE.test(key)) {
|
|
out[key] = REDACTED;
|
|
} else {
|
|
out[key] = redactObject(value, depth + 1);
|
|
}
|
|
}
|
|
return out;
|
|
}
|
|
|
|
/** Scrub cookies/auth headers and sensitive keys before sending to Sentry. */
|
|
export function redactSentryEvent(
|
|
event: ErrorEvent,
|
|
_hint: EventHint,
|
|
): ErrorEvent | null {
|
|
if (event.request) {
|
|
if (event.request.cookies) {
|
|
event.request.cookies =
|
|
REDACTED as unknown as typeof event.request.cookies;
|
|
}
|
|
if (event.request.headers) {
|
|
const headers = event.request.headers as Record<string, string>;
|
|
if (headers.cookie) headers.cookie = REDACTED;
|
|
if (headers.Cookie) headers.Cookie = REDACTED;
|
|
if (headers.authorization) headers.authorization = REDACTED;
|
|
if (headers.Authorization) headers.Authorization = REDACTED;
|
|
}
|
|
if (event.request.data) {
|
|
event.request.data = redactObject(
|
|
event.request.data,
|
|
) as typeof event.request.data;
|
|
}
|
|
}
|
|
if (event.extra)
|
|
event.extra = redactObject(event.extra) as typeof event.extra;
|
|
if (event.contexts) {
|
|
event.contexts = redactObject(event.contexts) as typeof event.contexts;
|
|
}
|
|
return event;
|
|
}
|