Scrub Authorization values from the forwarded PJSIP trace - #14
Merged
Conversation
onPJLog forwards whole SIP messages to CallWaveLog, and at debug level those messages carry Authorization/Proxy-Authorization digest responses — a derivative of the account password. Redaction was documented but enforced only by discipline (release defaults to warning), so a debug build shipped by mistake would leak credentials. The PJSIP sink now scrubs Authorization and Proxy-Authorization header values before forwarding, replacing them with <redacted> while keeping the header names readable. Scrubbing is tied to CallWaveLog.redactsIdentifiers: FIELD-TESTING deliberately disables redaction to inspect the raw trace, and that escape hatch is unchanged. Adds CallWaveLogScrubbingTests covering digest and proxy headers, case-insensitive matching, non-credential lines, the redaction-off pass-through and the trailing-newline shape.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Что
Закрывает последний пробел пункта 3 (диагностика и безопасность логов):
onPJLogпробрасывал PJSIP wire-trace вCallWaveLogкак есть, и на уровнеdebugтрейс содержалAuthorization:/Proxy-Authorization:digest-ответы — производную пароля аккаунта. Редактирование было задокументировано, но гарантировалось только дисциплиной (дефолт release —warning).Изменения
CallWaveLog— новый+scrubAuthorizationInMessage:(internal): заменяет значения заголовковAuthorization/Proxy-Authorizationна<redacted>, имена заголовков сохраняет, регистронезависимо, с fast-path и сохранением формы trailing newline.onPJLog— скраббинг перед форвардингом трейса.CallWaveLog.redactsIdentifiers: при выключенной редакции (осознанный escape hatch из FIELD-TESTING) трейс остаётся сырым — поведение задокументировано и не изменилось.CallWaveLogging.h,CallWaveTypes.h,CallWaveKit/README.md): формулировки «trace содержит Authorization» заменены на точное описание скраббинга.Тесты
CallWaveLogScrubbingTests— 6 кейсов: digest и proxy-заголовки, регистронезависимость и whitespace, строки без credentials (включая «Authorization» в теле), pass-through при выключенной редакции, форма trailing newline.Полный прогон
Scripts/run-package-tests.sh: все сьюты зелёные, 0 падений.Независим от #11/#12/#13 (другие участки кода), конфликтов нет.