fix: mask the provider reset url before logging it
net.reset() logged the full reset_url at INFO on the success path; a provider reset url can carry a rotation token in its query string, so this leaked it to logs. strip the query + fragment before logging (stdlib urlsplit, no new dependency - the core stays dependency-free) so the token cannot reach a log sink; scheme/host/path are kept for diagnostics. Signed-off-by: disqualifier <dev@disqualifier.me>
This commit is contained in:
+14
-1
@@ -6,11 +6,24 @@ calling a function without it raises a clear error.
|
|||||||
"""
|
"""
|
||||||
import logging
|
import logging
|
||||||
from typing import Optional, Union
|
from typing import Optional, Union
|
||||||
|
from urllib.parse import urlsplit, urlunsplit
|
||||||
|
|
||||||
from .proxy import Proxy, to_proxy
|
from .proxy import Proxy, to_proxy
|
||||||
|
|
||||||
log = logging.getLogger(__name__)
|
log = logging.getLogger(__name__)
|
||||||
|
|
||||||
|
|
||||||
|
def _safe_url(url: str) -> str:
|
||||||
|
"""strip query + fragment from a url for logging - a provider reset url can carry a
|
||||||
|
rotation token in its query/path; this drops the query/fragment (the usual token spot)
|
||||||
|
so the log line can't leak it. falls back to the raw url only if it won't parse"""
|
||||||
|
try:
|
||||||
|
parts = urlsplit(url)
|
||||||
|
except ValueError:
|
||||||
|
return url
|
||||||
|
return urlunsplit((parts.scheme, parts.netloc, parts.path, "", ""))
|
||||||
|
|
||||||
|
|
||||||
try:
|
try:
|
||||||
import aiohttp
|
import aiohttp
|
||||||
|
|
||||||
@@ -55,7 +68,7 @@ async def reset(reset_url: str, *, timeout: float = 15.0) -> bool:
|
|||||||
async with aiohttp.ClientSession(timeout=t) as session:
|
async with aiohttp.ClientSession(timeout=t) as session:
|
||||||
async with session.get(reset_url) as resp:
|
async with session.get(reset_url) as resp:
|
||||||
ok = resp.status == 200
|
ok = resp.status == 200
|
||||||
log.info("proxy reset %s -> %s", reset_url, resp.status)
|
log.info("proxy reset %s -> %s", _safe_url(reset_url), resp.status)
|
||||||
return ok
|
return ok
|
||||||
except Exception as exc:
|
except Exception as exc:
|
||||||
log.warning("proxy reset failed: %s", exc)
|
log.warning("proxy reset failed: %s", exc)
|
||||||
|
|||||||
Reference in New Issue
Block a user