/** * The scrubber is part of the auth boundary, not a nicety. * * On this platform a phone number is the login identity and a 6-digit OTP is * the credential. If either reaches Bugsink, anyone with access to the error * tracker can sign in as that user — so these tests assert the redaction, not * the happy path. */ import { describe, expect, it } from 'vitest'; import { beforeSend, REDACTED, scrub } from '../src/lib/observability'; type Event = Parameters[0]; describe('scrub', () => { it('redacts secret-bearing keys wherever they are nested', () => { const out = scrub({ safe: 'keep me', phoneNumber: '+34600111222', nested: { deeper: { token: 'abc123', otp: '445566' } }, }) as { safe: string; phoneNumber: string; nested: { deeper: { token: string; otp: string } }; }; expect(out.safe).toBe('keep me'); expect(out.phoneNumber).toBe(REDACTED); expect(out.nested.deeper.token).toBe(REDACTED); expect(out.nested.deeper.otp).toBe(REDACTED); }); it('redacts a phone number found in free text, not just in a named field', () => { const out = scrub('failed to send to +34600111222 after 3 tries'); expect(out).not.toContain('600111222'); expect(out).toContain(REDACTED); }); it('redacts a bare six-digit code, which is the shape of our OTP', () => { expect(scrub('code 123456 expired')).toBe(`code ${REDACTED} expired`); }); it('survives a circular object rather than throwing away the report', () => { const a: Record = { name: 'x' }; a.self = a; expect(() => scrub(a)).not.toThrow(); }); it('walks arrays', () => { const out = scrub([{ token: 'a' }, { safe: 'b' }]) as Array>; expect(out[0]!.token).toBe(REDACTED); expect(out[1]!.safe).toBe('b'); }); }); describe('beforeSend', () => { it('drops cookies and headers entirely', () => { const event = { request: { url: 'https://linkdr.app/api', cookies: { session: 'live-credential' }, headers: { authorization: 'Bearer live-credential' }, }, } as unknown as Event; const out = beforeSend(event)!; expect(out.request?.cookies).toBeUndefined(); expect(out.request?.headers).toBeUndefined(); }); it('reduces the user to an id — never a phone or email', () => { const event = { user: { id: 'user-1', email: 'someone@example.com', phone: '+34600111222' }, } as unknown as Event; const out = beforeSend(event)!; expect(out.user).toEqual({ id: 'user-1' }); }); it('scrubs a phone number out of the exception message', () => { const event = { exception: { values: [{ value: 'no user for +34600111222' }] }, } as unknown as Event; const out = beforeSend(event)!; expect(out.exception!.values![0]!.value).not.toContain('600111222'); }); it('scrubs request body data and the query string', () => { const event = { request: { url: 'https://linkdr.app/verify?code=123456', query_string: 'code=123456', data: { phoneNumber: '+34600111222', code: '123456' }, }, } as unknown as Event; const out = beforeSend(event)!; expect(out.request!.query_string).not.toContain('123456'); expect(out.request!.url).not.toContain('123456'); expect((out.request!.data as Record).phoneNumber).toBe(REDACTED); }); it('scrubs breadcrumbs, which is where fetch URLs accumulate', () => { const event = { breadcrumbs: [{ message: 'POST /phone-number/verify +34600111222', data: { code: '123456' } }], } as unknown as Event; const out = beforeSend(event)!; expect(out.breadcrumbs![0]!.message).not.toContain('600111222'); expect((out.breadcrumbs![0]!.data as Record).code).toBe(REDACTED); }); });