mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-11 14:00:29 +00:00
e0edbaf7d0
The Telegram bot token redaction had an off-by-one bug: it searched for the next "/" starting from the "/bot" position, which found the "/" in "/bot" itself (offset 0) instead of the next "/" after the token. Result: tokens were not properly redacted and the URL got corrupted with duplicated path segments, potentially leaking secrets to logs/API responses. Fix: search from idx+4 (after "/bot") and handle edge cases where there's no trailing slash (token at end of URL or before query string). Added 20 comprehensive test cases covering: - No secrets (passthrough) - Telegram bot tokens (various patterns) - Query parameter secrets (token, apikey, api_key, key, secret, password) - Multiple parameters and edge cases
Internal API Package
This directory contains the API server implementation for Pulse.
Important Note About frontend-modern/
The frontend-modern/ subdirectory that appears here is:
- AUTO-GENERATED during builds
- NOT the source code - just a build artifact
- IN .gitignore - never committed
- REQUIRED BY GO - The embed directive needs it here
Frontend Development Location
👉 Edit frontend files at: /opt/pulse/frontend-modern/src/
Why This Structure?
Go's //go:embed directive has limitations:
- Cannot use
../paths to access parent directories - Cannot follow symbolic links
- Must embed files within the Go module
This is a known Go limitation and our structure works around it.