fix(svc): scrub streaming responses in the sanitize interceptor #25

Merged
nalum merged 1 commit from fix/stream-sanitize into main 2026-08-13 11:38:47 +00:00
Owner

WrapStreamingHandler returned next untouched, so the structural scrub guarantee was unary-only. A future streaming RPC emitting a User would have leaked password_hash/pin_hash with nothing failing.

The interceptor now wraps the streaming conn and runs the same recursive scrub walk (including has_pin derivation) on every Send. Tests cover a streamed User (secrets cleared), a Notification (byte-identical pass-through), and error propagation.

Fixes #21

🤖 Generated with Claude Code

`WrapStreamingHandler` returned `next` untouched, so the structural scrub guarantee was unary-only. A future streaming RPC emitting a `User` would have leaked `password_hash`/`pin_hash` with nothing failing. The interceptor now wraps the streaming conn and runs the same recursive scrub walk (including `has_pin` derivation) on every `Send`. Tests cover a streamed `User` (secrets cleared), a `Notification` (byte-identical pass-through), and error propagation. Fixes #21 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(svc): scrub streaming responses in the sanitize interceptor
All checks were successful
check / go (push) Successful in 1m43s
check / web (push) Successful in 1m38s
4105d47fa0
WrapStreamingHandler returned next untouched, so the structural scrub
guarantee held for unary responses only. Today's streams (Watch's
DataChange, Subscribe's Notification) carry no scrub-map fields, but a
future streaming RPC emitting a User would have leaked password_hash
and pin_hash silently. Wrapping the handler conn so Send runs the same
recursive scrub walk closes that gap before any secret-bearing stream
exists.

Fixes #21
nalum force-pushed fix/stream-sanitize from 4105d47fa0
All checks were successful
check / go (push) Successful in 1m43s
check / web (push) Successful in 1m38s
to cfc070cfe4
Some checks failed
tag / tag (push) Has been cancelled
check / go (push) Successful in 1m46s
check / web (push) Successful in 1m27s
2026-08-13 11:33:34 +00:00
Compare
nalum scheduled this pull request to auto merge when all checks succeed 2026-08-13 11:34:00 +00:00
nalum merged commit cfc070cfe4 into main 2026-08-13 11:38:47 +00:00
nalum deleted branch fix/stream-sanitize 2026-08-13 11:38:48 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!25
No description provided.