The showcase was a Barcelona market: Catalan names, +34 numbers, euro rates and "Carrer Example 12" on every job. Presented to a Mexican client, all of that reads as somebody else's product. City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at 19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were Barcelona literals, so an unset env quietly seeded a different city than the app rendered — they now agree. Two db tests pinned the Barcelona centre as a hardcoded constant, which is why the deck returned zero cards on the first run here: every pro was a continent outside the radius. They read the same env as the seed now, so the trap cannot recur. Money: formatCents defaults to USD/en-US, and the nine hardcoded euro signs across the card, search rows, quote strip and forms are dollars. The rate NUMBERS are unchanged and still read high for CDMX — that is a pricing decision, not a currency one, and is left alone deliberately. Seed people are Mexican, addressed on real Roma/Condesa streets rotated by index rather than one placeholder repeated. Phones moved to +52 55, which moves the demo login to +525500000000 / 000000. Also in here, from the same session: - Sending a job now confirms. The mutation always succeeded; the sheet just closed with no receipt, which from the customer's side is indistinguishable from a dead button. Dismissing that receipt resolves as 'sent', so the card does not return to the deck. - Media moves to DigitalOcean Spaces, with the public origin derived from bucket and region instead of a second env var to keep in sync. - Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM. - The client-facing project panel beside the running app. - Two profiles removed and four renamed to match their photos. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
113 lines
3.8 KiB
TypeScript
113 lines
3.8 KiB
TypeScript
/**
|
|
* The scrubber is part of the auth boundary, not a nicety.
|
|
*
|
|
* On this platform a phone number is the login identity and a 6-digit OTP is
|
|
* the credential. If either reaches Bugsink, anyone with access to the error
|
|
* tracker can sign in as that user — so these tests assert the redaction, not
|
|
* the happy path.
|
|
*/
|
|
import { describe, expect, it } from 'vitest';
|
|
import { beforeSend, REDACTED, scrub } from '../src/lib/observability';
|
|
|
|
type Event = Parameters<typeof beforeSend>[0];
|
|
|
|
describe('scrub', () => {
|
|
it('redacts secret-bearing keys wherever they are nested', () => {
|
|
const out = scrub({
|
|
safe: 'keep me',
|
|
phoneNumber: '+34600111222',
|
|
nested: { deeper: { token: 'abc123', otp: '445566' } },
|
|
}) as {
|
|
safe: string;
|
|
phoneNumber: string;
|
|
nested: { deeper: { token: string; otp: string } };
|
|
};
|
|
|
|
expect(out.safe).toBe('keep me');
|
|
expect(out.phoneNumber).toBe(REDACTED);
|
|
expect(out.nested.deeper.token).toBe(REDACTED);
|
|
expect(out.nested.deeper.otp).toBe(REDACTED);
|
|
});
|
|
|
|
it('redacts a phone number found in free text, not just in a named field', () => {
|
|
const out = scrub('failed to send to +34600111222 after 3 tries');
|
|
expect(out).not.toContain('600111222');
|
|
expect(out).toContain(REDACTED);
|
|
});
|
|
|
|
it('redacts a bare six-digit code, which is the shape of our OTP', () => {
|
|
expect(scrub('code 123456 expired')).toBe(`code ${REDACTED} expired`);
|
|
});
|
|
|
|
it('survives a circular object rather than throwing away the report', () => {
|
|
const a: Record<string, unknown> = { name: 'x' };
|
|
a.self = a;
|
|
expect(() => scrub(a)).not.toThrow();
|
|
});
|
|
|
|
it('walks arrays', () => {
|
|
const out = scrub([{ token: 'a' }, { safe: 'b' }]) as Array<Record<string, string>>;
|
|
expect(out[0]!.token).toBe(REDACTED);
|
|
expect(out[1]!.safe).toBe('b');
|
|
});
|
|
});
|
|
|
|
describe('beforeSend', () => {
|
|
it('drops cookies and headers entirely', () => {
|
|
const event = {
|
|
request: {
|
|
url: 'https://linkdr.app/api',
|
|
cookies: { session: 'live-credential' },
|
|
headers: { authorization: 'Bearer live-credential' },
|
|
},
|
|
} as unknown as Event;
|
|
|
|
const out = beforeSend(event)!;
|
|
expect(out.request?.cookies).toBeUndefined();
|
|
expect(out.request?.headers).toBeUndefined();
|
|
});
|
|
|
|
it('reduces the user to an id — never a phone or email', () => {
|
|
const event = {
|
|
user: { id: 'user-1', email: 'someone@example.com', phone: '+34600111222' },
|
|
} as unknown as Event;
|
|
|
|
const out = beforeSend(event)!;
|
|
expect(out.user).toEqual({ id: 'user-1' });
|
|
});
|
|
|
|
it('scrubs a phone number out of the exception message', () => {
|
|
const event = {
|
|
exception: { values: [{ value: 'no user for +34600111222' }] },
|
|
} as unknown as Event;
|
|
|
|
const out = beforeSend(event)!;
|
|
expect(out.exception!.values![0]!.value).not.toContain('600111222');
|
|
});
|
|
|
|
it('scrubs request body data and the query string', () => {
|
|
const event = {
|
|
request: {
|
|
url: 'https://linkdr.app/verify?code=123456',
|
|
query_string: 'code=123456',
|
|
data: { phoneNumber: '+34600111222', code: '123456' },
|
|
},
|
|
} as unknown as Event;
|
|
|
|
const out = beforeSend(event)!;
|
|
expect(out.request!.query_string).not.toContain('123456');
|
|
expect(out.request!.url).not.toContain('123456');
|
|
expect((out.request!.data as Record<string, string>).phoneNumber).toBe(REDACTED);
|
|
});
|
|
|
|
it('scrubs breadcrumbs, which is where fetch URLs accumulate', () => {
|
|
const event = {
|
|
breadcrumbs: [{ message: 'POST /phone-number/verify +34600111222', data: { code: '123456' } }],
|
|
} as unknown as Event;
|
|
|
|
const out = beforeSend(event)!;
|
|
expect(out.breadcrumbs![0]!.message).not.toContain('600111222');
|
|
expect((out.breadcrumbs![0]!.data as Record<string, string>).code).toBe(REDACTED);
|
|
});
|
|
});
|