Skip to content

Minimize hosted diagnostics and prevent referrer disclosure - #2143

Merged
RhysSullivan merged 4 commits into
mainfrom
security/casa-diagnostics-20260928
Sep 28, 2026
Merged

RhysSullivan merged 4 commits into
mainfrom
security/casa-diagnostics-20260928

Conversation

@RhysSullivan

@RhysSullivan RhysSullivan commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Hosted auth, billing and MCP failures could forward raw provider errors into console logs, traces and Sentry. This change minimizes those payloads while preserving allowed failure classifications, source positions and correlation IDs. Cloudflare query-string redaction and Referrer-Policy: no-referrer protect credential-bearing URLs.

Existing diagnostic assertions are updated with the code so this PR can pass independently. New privacy and content-boundary coverage is in #2144. Verification: format and lint pass; all 45 typecheck tasks pass; the browser error-reporting and rejected-database-write scenarios pass. Format, lint, typecheck and the complete non-e2e suite passed CI for the identical combined source tree before the final restack. Checks on the new branch heads are pending.

This reuses and narrows the diagnostics work from #2112, without changing JWT lifetime enforcement. Production verification follows deployment.

@RhysSullivan
RhysSullivan added this pull request to stack #2145 September 28, 2026 18:16
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
executor-cloud af536cf Sep 28 2026, 06:39 PM

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
executor-marketing af536cf Commit Preview URL

Branch Preview URL
Sep 28 2026, 06:37 PM

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Cloudflare preview

Torn down — the PR is closed.

@pkg-pr-new

pkg-pr-new Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@executor-js/cli

npm i https://pkg.pr.new/@executor-js/cli@2143

@executor-js/config

npm i https://pkg.pr.new/@executor-js/config@2143

@executor-js/execution

npm i https://pkg.pr.new/@executor-js/execution@2143

@executor-js/sdk

npm i https://pkg.pr.new/@executor-js/sdk@2143

@executor-js/codemode-core

npm i https://pkg.pr.new/@executor-js/codemode-core@2143

@executor-js/runtime-quickjs

npm i https://pkg.pr.new/@executor-js/runtime-quickjs@2143

@executor-js/plugin-file-secrets

npm i https://pkg.pr.new/@executor-js/plugin-file-secrets@2143

@executor-js/plugin-graphql

npm i https://pkg.pr.new/@executor-js/plugin-graphql@2143

@executor-js/plugin-keychain

npm i https://pkg.pr.new/@executor-js/plugin-keychain@2143

@executor-js/plugin-mcp

npm i https://pkg.pr.new/@executor-js/plugin-mcp@2143

@executor-js/plugin-onepassword

npm i https://pkg.pr.new/@executor-js/plugin-onepassword@2143

@executor-js/plugin-openapi

npm i https://pkg.pr.new/@executor-js/plugin-openapi@2143

executor

npm i https://pkg.pr.new/executor@2143

commit: af536cf

@RhysSullivan
RhysSullivan marked this pull request as ready for review September 28, 2026 18:43
@RhysSullivan
RhysSullivan merged commit 7c26543 into main Sep 28, 2026
79 of 80 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant