Filter secrets from logged query strings and Referer/Location URLs - #29
Merged
Merged
Conversation
HTTPEvents logs the raw query string, so ?password=hunter2&token=... is stored verbatim, and so are the queries of the URLs in the Referer request header and the Location response header. The tests pin a query_string_filters setting that works like Rails' filter_parameters: the default list, a custom list, Regexps, an empty list to disable filtering, nested and URL-encoded names, Referer and Location in either casing, the collapsed event, and the rest of the string left byte for byte unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adds HTTPEvents.query_string_filters, a class-level list like http_header_filters, defaulting to DEFAULT_QUERY_STRING_FILTERS (the list Rails puts in new apps, minus email). Like Rails' filter_parameters, a String or Symbol filters every parameter whose URL-decoded name contains it, ignoring case, a Regexp every name it matches, and other entries such as Procs are ignored. Nested names are matched as the full decoded name. A matching parameter's value becomes [FILTERED] and the rest of the string stays byte for byte unchanged. The filters apply to the query string of http_request_received and to the query of the URLs in the Referer and Location headers, whatever their casing, so the collapsed event is covered too. An empty list disables the filtering. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 1, 2026
PetrHeinz
marked this pull request as ready for review
October 2, 2026 09:18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HTTPEventslogs the raw query string, so?password=hunter2&token=…lands inhttp_request_received.query_stringverbatim. The queries of the URLs in theRefererrequest header and theLocationresponse header are stored raw inheaders_jsontoo. Yesterday's red-team foundpassword=hunter2andtoken=values in plain text in Rack, Sinatra and on all seven Rails versions, while Rails' own params on the same request showed[FILTERED].What changes:
HTTPEvents.query_string_filterssetting, a class-level list likehttp_header_filters. It defaults toDEFAULT_QUERY_STRING_FILTERS = %w[passw secret token _key crypt salt certificate otp ssn cvv cvc], which is the list Rails puts in new apps, minusemail.filter_parameters: a String or Symbol filters every parameter whose name contains it, ignoring case, and a Regexp filters every name it matches (=~). Other entries, such as the Procs Rails allows, are ignored.user[password]anduser%5Bpassword%5Dare both filtered.[FILTERED]. The rest of the string stays byte for byte unchanged, including the parameter name, separators, empty values and parameters without a value.query_string, and to the query part ofRefererandLocationinheaders_json, whatever the header's casing. That includes the single event of collapsed mode (collapse_into_single_event/logrageify!).[]disables the filtering.Behaviour and compatibility:
Referer/LocationURLs now carry[FILTERED]for matching parameters, where they had the raw value before. Setting the list to[]restores the old output.filtered_query_string(and Rack before 3.0), both∧separate parameters. A filtered value runs up to the next separator, sotoken=abc=defbecomestoken=[FILTERED].LocationURL isn't touched, and neither are paths, which never contain the query in these events.config.filter_parametersinstead of this default (separate PR, targeting the logtail-rails 0.3.0 minor).Targets the 0.2.9 patch release. The logtail-rails PR that applies
filter_parametersto URLs runs its CI against this branch until 0.2.9 is released.The first commit only adds the tests and is expected to fail on CI; the second commit makes them pass.
🤖 Generated with Claude Code