2 Commits
Author SHA1 Message Date
dsql 4d5caac8d8 chore: bump to 1.1.0 (logging-discipline audit)
Signed-off-by: disqualifier <dev@disqualifier.me>
2026-08-10 23:00:50 -04:00
dsql 5699aa9dde fix: mask the provider reset url before logging it
net.reset() logged the full reset_url at INFO on the success path; a provider reset url
can carry a rotation token in its query string, so this leaked it to logs. strip the
query + fragment before logging (stdlib urlsplit, no new dependency - the core stays
dependency-free) so the token cannot reach a log sink; scheme/host/path are kept for
diagnostics.

Signed-off-by: disqualifier <dev@disqualifier.me>
2026-08-09 02:10:45 -04:00
2 changed files with 15 additions and 2 deletions
+1 -1
View File
@@ -4,7 +4,7 @@ build-backend = "hatchling.build"
[project]
name = "aioproxies"
version = "1.0.0"
version = "1.1.0"
description = "proxy parsing, formatting, health, and pool management for aiohttp/aioweb, camoufox, and socks5"
requires-python = ">=3.10"
dependencies = []
+14 -1
View File
@@ -6,11 +6,24 @@ calling a function without it raises a clear error.
"""
import logging
from typing import Optional, Union
from urllib.parse import urlsplit, urlunsplit
from .proxy import Proxy, to_proxy
log = logging.getLogger(__name__)
def _safe_url(url: str) -> str:
"""strip query + fragment from a url for logging - a provider reset url can carry a
rotation token in its query/path; this drops the query/fragment (the usual token spot)
so the log line can't leak it. falls back to the raw url only if it won't parse"""
try:
parts = urlsplit(url)
except ValueError:
return url
return urlunsplit((parts.scheme, parts.netloc, parts.path, "", ""))
try:
import aiohttp
@@ -55,7 +68,7 @@ async def reset(reset_url: str, *, timeout: float = 15.0) -> bool:
async with aiohttp.ClientSession(timeout=t) as session:
async with session.get(reset_url) as resp:
ok = resp.status == 200
log.info("proxy reset %s -> %s", reset_url, resp.status)
log.info("proxy reset %s -> %s", _safe_url(reset_url), resp.status)
return ok
except Exception as exc:
log.warning("proxy reset failed: %s", exc)