Skip to content

fix(apirouter): keep destination credentials out of attempts and request logs - #1095

Merged
alexluong merged 2 commits into
mainfrom
fix/attempt-destination-credentials
Sep 28, 2026
Merged

alexluong merged 2 commits into
mainfrom
fix/attempt-destination-credentials

Conversation

@alexluong

Copy link
Copy Markdown
Collaborator

Closes #1094.

include=destination on GET /attempts, GET /attempts/:id, and GET /tenants/:tenant_id/destinations/:destination_id/attempts now returns the destination without credentials. Credentials are only returned by the destination endpoints.

The request body logged on 5xx responses now redacts every credential value. Before, redaction depended on provider metadata, so webhook secrets (not marked sensitive) and PATCH bodies (no type to load metadata from) were logged in plaintext.

Breaking

Callers reading credentials from an embedded destination on attempts no longer get them. Use GET /tenants/:tenant_id/destinations/:destination_id.

Spec: open question

Every per-type Destination* schema requires credentials, so the embedded destination no longer matches Destination. Two options:

  • A (this PR): a new AttemptDestination schema for attempt.destination. The Destination schema and destination endpoints are unchanged. Attempts lose per-type typing: config becomes a generic string map in the SDKs.
  • B: make credentials optional in every Destination* schema. Attempts keep the typed per-type destination. Every SDK's Destination type changes; in Go, Credentials likely becomes a pointer, which breaks callers reading it from destination endpoints.

Going with A for now. Input welcome.

Tests

  • TestAPI_Attempts: include=destination responses have no credentials key.
  • TestRequestBodySanitizer_RedactsAllCredentials: a body without type still has its credentials redacted.

🤖 Generated with Claude Code

alexluong and others added 2 commits September 26, 2026 00:17
Attempts embed the destination without credentials. Credentials are only
returned by the destination endpoints.

The spec gets an AttemptDestination schema, since the per-type
Destination schemas require credentials.

Refs #1094

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Redaction relied on provider metadata, which skipped credentials not
marked sensitive (webhook secrets) and bodies without a type (PATCH).
Every credential value is now redacted.

Refs #1094

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@alexluong
alexluong merged commit d0342db into main Sep 28, 2026
5 checks passed
@alexluong
alexluong deleted the fix/attempt-destination-credentials branch September 28, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Credentials exposed outside destination endpoints

2 participants