Skip to content

fix(security): send credential headers by name only in detection reports - #62

Open
cport1 wants to merge 1 commit into
mainfrom
fix/send-client-signals-not-headers
Open

cport1 wants to merge 1 commit into
mainfrom
fix/send-client-signals-not-headers

Conversation

@cport1

@cport1 cport1 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Detection reports sent the request's full header map, so a visitor's Cookie, Authorization and API key headers were sent to WebDecoy. None of those values is needed to score a request.

  • toWireDetectionRequest, the one function that shapes a report, now passes headers through reportableHeaders(). Credential headers keep their name and get an empty value. cookie is cut down to WebDecoy's own wd_clearance cookie, which the service uses to recognise a cleared client.
  • Credential headers are matched by name with a substring pattern (cookie|auth|token|secret|passw|session|credential|csrf|xsrf|api-key|access-key|private-key), so names nobody listed are caught too. The ingest service enforces the same pattern for older SDK versions.
  • Rules and characteristics still run on the full request. Only the outgoing report is redacted.

Tests:

  • report-headers.test.ts sends the header map the adapters forward through client.detect and checks that no credential value is on the wire, every header name is, evidence headers keep their values, and the caller's object is not mutated.
  • invariants.test.ts checks that the detect endpoint has exactly one caller and that it goes through toWireDetectionRequest.
  • Both fail when the redaction is removed.

npm run build, lint, test (582 tests) and check:edge pass.

Detection reports carried the request's full header map, so a visitor's
session cookie, bearer token or API key header was sent with every report.
toWireDetectionRequest now replaces credential header values with an empty
string and keeps only WebDecoy's own wd_clearance cookie. Rules still see the
full request.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant