Conversation
DescriptionThis pull request resolves a medium-severity sensitive data logging vulnerability in advanced-wallets (F-02), identified during the workspace security audit. Previously, handleSendMany.ts serialized full transaction prebuild objects (txPrebuilt) and raw signing keychain payloads to the application logs. Keychains may contain sensitive cryptographic fields such as encryptedPrv, and serialized transaction prebuilds expose raw PSBT hexes, public keys, and full recipient metadata in log aggregators. Summary of ChangesSanitized Event Logging: Removed object-level logging of txPrebuilt and signingKeychain. Replaced inline public-key interpolation with generic audit messages (logger.debug('Transaction prebuild verified') and logger.info('Signing with <source> keychain')). Preserved Diagnostic Error Tracing: Retained exception message reporting (err.message) to support operational troubleshooting without dumping underlying sensitive payloads to logger.error. Defensive Test Assertions: Added unit test assertions in src/_tests/api/master/sendMany.test.ts to inspect all logger stubs (error, warn, info, http, debug) and verify that public keys (xpub_user), key IDs, PSBT hex strings, and raw transaction components are never emitted during successful flows or validation failures. Issue NumberBG-F02-SENSITIVE-LOGGING Type of change[x] Bug fix (non-breaking change which fixes an issue)[ ] New feature (non-breaking change which adds functionality)[ ] Breaking change (fix or feature that would cause existing functionality to not work as expected)[ ] This change requires a documentation updateHow Has This Been Tested?Tested locally using Supertest, Mocha, Sinon, and Nock against the Master BitGo Express endpoint test suite. Reproduction InstructionsRun targeted unit tests for sendMany:Bashnpm run test -- src/_tests/api/master/sendMany.test.ts
Verified Test CasesClean Success Logging: Asserted that successful sendMany transactions emit generic informational logs without leaking xpub_user, user-key-id, or prebuild hex strings. Local Validation Failure: Verified that when verifyTransaction returns false, only the sanitized validation error message is logged. Validation Exception: Verified that when verifyTransaction throws an unexpected error, only the error message is logged without raw transaction objects. Checklist: [x] My code follows the style guidelines of this project [x] I have performed a self-review of my own code [x] My code compiles correctly for both Node and Browser environments [x] I have commented my code, particularly in hard-to-understand areas [x] My commits follow Conventional Commits and I have properly described any BREAKING CHANGES [x] The ticket or github issue was included in the commit message as a reference [x] I have made corresponding changes to the documentation and on any new/updated functions and/or methods - jsdoc[x] I have added tests that prove my fix is effective or that my feature works[x] New and existing unit tests pass locally with my changes
OttoAllmendinger
approved these changes
Sep 18, 2026
pranavjain97
approved these changes
Sep 24, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This pull request resolves a medium-severity sensitive data logging vulnerability in
advanced-wallets(F-02), identified during the workspace security audit.Previously,
handleSendMany.tsserialized full transaction prebuild objects (txPrebuilt) and raw signing keychain payloads to the application logs. Keychains may contain sensitive cryptographic fields such asencryptedPrv, and serialized transaction prebuilds expose raw PSBT hexes, public keys, and full recipient metadata in log aggregators.Summary of Changes
txPrebuiltandsigningKeychain[cite: 24]. Replaced inline public-key interpolation with generic audit messages (logger.debug('Transaction prebuild verified')andlogger.info('Signing with <source> keychain'))[cite: 24].err.message) to support operational troubleshooting without dumping underlying sensitive payloads tologger.error[cite: 24].src/_tests/api/master/sendMany.test.tsto inspect all logger stubs (error,warn,info,http,debug) and verify that public keys (xpub_user), key IDs, PSBT hex strings, and raw transaction components are never emitted during successful flows or validation failures[cite: 24].Issue Number
BG-F02-SENSITIVE-LOGGING[cite: 24]
Type of change
How Has This Been Tested?
Tested locally using Supertest, Mocha, Sinon, and Nock against the Master BitGo Express endpoint test suite[cite: 24].
Reproduction Instructions
Run targeted unit tests for
sendMany: