fix(settings): harden settings and diagnostic controls

This commit is contained in:
NimBold
2026-07-17 00:39:26 +03:30
parent 5144ecd39e
commit 6ef911919d
10 changed files with 226 additions and 18 deletions
+17
View File
@@ -5868,6 +5868,7 @@ async fn log_files(app_handle: &tauri::AppHandle) -> Result<Vec<std::path::PathB
pub(crate) fn redact_sensitive_text(line: &str) -> String {
use std::sync::OnceLock;
static SECRET: OnceLock<regex::Regex> = OnceLock::new();
static QUOTED_SECRET: OnceLock<regex::Regex> = OnceLock::new();
static HEADER: OnceLock<regex::Regex> = OnceLock::new();
static QUERY: OnceLock<regex::Regex> = OnceLock::new();
static USERINFO: OnceLock<regex::Regex> = OnceLock::new();
@@ -5878,6 +5879,12 @@ pub(crate) fn redact_sensitive_text(line: &str) -> String {
)
.expect("valid secret redaction regex")
});
let quoted_secret = QUOTED_SECRET.get_or_init(|| {
regex::Regex::new(
r#"(?i)(["'])(authorization|proxy-authorization|cookie|set-cookie|password|token|secret|credential|pairing[-_ ]?token|api[-_ ]?key)(["'])(\s*[:=]\s*)["'][^"\r\n,;]*["']"#,
)
.expect("valid quoted secret redaction regex")
});
let header = HEADER.get_or_init(|| {
regex::Regex::new(
r"(?i)(authorization|proxy-authorization|cookie|set-cookie)\s*:\s*[^\r\n]+",
@@ -5897,6 +5904,7 @@ pub(crate) fn redact_sensitive_text(line: &str) -> String {
.expect("valid URL fragment redaction regex")
});
let redacted = header.replace_all(line, "$1: [redacted]");
let redacted = quoted_secret.replace_all(&redacted, "$1$2$3$4[redacted]");
let redacted = secret.replace_all(&redacted, "$1=[redacted]");
let redacted = userinfo.replace_all(&redacted, "$1[redacted]@");
let redacted = query.replace_all(&redacted, "$1?[redacted]");
@@ -7092,6 +7100,15 @@ mod tests {
assert!(redacted.contains("http://[redacted]@example.com/file#[redacted]"));
}
#[test]
fn redacts_quoted_json_credentials() {
let line = r#"{"api_key":"json-secret","cookie":"session=secret"}"#;
let redacted = redact_log_line(line);
assert!(!redacted.contains("json-secret"));
assert!(!redacted.contains("session=secret"));
assert!(redacted.contains("[redacted]"));
}
#[test]
fn collects_primary_url_and_unique_mirrors_in_order() {
let uris = collect_download_uris(