fix(svc): scrub streaming responses in the sanitize interceptor #25
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!25
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/stream-sanitize"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
WrapStreamingHandlerreturnednextuntouched, so the structural scrub guarantee was unary-only. A future streaming RPC emitting aUserwould have leakedpassword_hash/pin_hashwith nothing failing.The interceptor now wraps the streaming conn and runs the same recursive scrub walk (including
has_pinderivation) on everySend. Tests cover a streamedUser(secrets cleared), aNotification(byte-identical pass-through), and error propagation.Fixes #21
🤖 Generated with Claude Code
4105d47fa0cfc070cfe4