security: strip Axios config/request objects from serialized error re…#653
Open
Nareshkumawat-star wants to merge 1 commit into
Open
security: strip Axios config/request objects from serialized error re…#653Nareshkumawat-star wants to merge 1 commit into
Nareshkumawat-star wants to merge 1 commit into
Conversation
|
Someone is attempting to deploy a commit to the omkh4242g-1671's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
Hi @Nareshkumawat-star, thanks for contributing to Debugra! 🎉 I have automatically:
Our workflows will now analyze your changes to classify:
Tip Ensure your PR description references the issue it resolves (e.g. Happy coding! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
✦ Description
Fixes a security concern where sensitive credentials (such as the server-side
GROQ_API_KEY) were leaked inside Axios error objects/stack traces when the Express server encountered an HTTP error during requests to third-party endpoints (e.g. Groq AI API) in development mode (NODE_ENV=development).**##Fixes #652 **
Cause:
When Axios requests fail, they throw an
AxiosErrorcontainingconfigandrequestproperties. IfNODE_ENV=developmentis active, the centralized error handler would return the error, exposingconfig.headers.Authorizationcontaining the raw API key in the response body.Fix:
Updated the error handler middleware in
server/middleware/errorHandler.jsto explicitly striperr.configanderr.requestfrom the error object before serializing or logging: