fix: mask get_application credentials and project the server row - #333
Conversation
…rver row (#332) Same class as #328: the application detail passthrough carried the manual webhook HMAC secrets (forgeable deploys), the basic-auth password, custom_labels (htpasswd hashes), and the entire nested destination.server row — settings blob, sentinel token, log-drain credentials, full proxy configuration. get_application masks the #209 sensitive-field list by default with reveal: true opt-in (webhook secrets and compose bodies have legitimate reveal uses); embedded server rows are projected down to the summary shape unconditionally and reveal never brings them back. updateApplication responses and the non-summary listApplications path get the same treatment. The projection is also a large token win: the raw payload embeds the whole proxy compose file. Closes #332.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #333 +/- ##
==========================================
+ Coverage 93.64% 93.67% +0.02%
==========================================
Files 4 4
Lines 740 743 +3
Branches 205 205
==========================================
+ Hits 693 696 +3
Misses 6 6
Partials 41 41 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Review: mask
|
…tial branches on the patch as misses
Review — #333 (mask
|
Closes #332. Same treatment as #331: mask the #209 sensitive-field list on
get_application/updateApplication/ non-summarylistApplicationswithreveal: trueopt-in on get, and project embeddeddestination.serverrows to the summary shape unconditionally. Four new tests with never-contains-secret assertions;get_applicationcontract snapshot regenerated. Found live: reading an app's config through the MCP returned the deploy-webhook HMAC keys and the server's log-drain credentials in the clear.