fix(apirouter): keep destination credentials out of attempts and request logs - #1095
Merged
Merged
Conversation
Attempts embed the destination without credentials. Credentials are only returned by the destination endpoints. The spec gets an AttemptDestination schema, since the per-type Destination schemas require credentials. Refs #1094 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Redaction relied on provider metadata, which skipped credentials not marked sensitive (webhook secrets) and bodies without a type (PATCH). Every credential value is now redacted. Refs #1094 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
alexbouchardd
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1094.
include=destinationonGET /attempts,GET /attempts/:id, andGET /tenants/:tenant_id/destinations/:destination_id/attemptsnow returns the destination withoutcredentials. Credentials are only returned by the destination endpoints.The request body logged on 5xx responses now redacts every credential value. Before, redaction depended on provider metadata, so webhook secrets (not marked sensitive) and PATCH bodies (no
typeto load metadata from) were logged in plaintext.Breaking
Callers reading
credentialsfrom an embedded destination on attempts no longer get them. UseGET /tenants/:tenant_id/destinations/:destination_id.Spec: open question
Every per-type
Destination*schema requirescredentials, so the embedded destination no longer matchesDestination. Two options:AttemptDestinationschema forattempt.destination. TheDestinationschema and destination endpoints are unchanged. Attempts lose per-type typing:configbecomes a generic string map in the SDKs.credentialsoptional in everyDestination*schema. Attempts keep the typed per-type destination. Every SDK'sDestinationtype changes; in Go,Credentialslikely becomes a pointer, which breaks callers reading it from destination endpoints.Going with A for now. Input welcome.
Tests
TestAPI_Attempts:include=destinationresponses have nocredentialskey.TestRequestBodySanitizer_RedactsAllCredentials: a body withouttypestill has its credentials redacted.🤖 Generated with Claude Code