Hacker News new | ask | show | jobs
by mmakeev 28 days ago
One question about http mode, you carry authorization headers. Do you redact bearer tokens before captures hit the logs?
1 comments

There's nothing redacted because the header isn't collected in the first place. Under http mode, the proxy intercepts the JSON-RPC messages, but not their headers, so there's no way for the log to contain the Authorization header and the bearer passes through unlogged. The contents of the messages themselves aren't redacted, which means if the secret is in the payload, it'll end up in the trace. The trace stays on your machine, and if you don't want anything to go to the disk at all, use --no-trace.
thanks! all clear