Skip to content

Keep host names out of error reports - #1938

Merged
BarganConstantin merged 1 commit into
developmentfrom
fix/error-origins
Oct 4, 2026
Merged

BarganConstantin merged 1 commit into
developmentfrom
fix/error-origins

Conversation

@BarganConstantin

Copy link
Copy Markdown
Owner

What changes

  • Error reports no longer carry the host of any web address. A deck opened from another machine by its name (for example http://alices-macbook.local:4317/) used to send that name in every frame of a page error. Both scrubs (the server's, which runs on every error that leaves, and the page's, which runs on the crash text seeded into the feedback dialog) now replace the scheme-and-host of every http(s):// and ws(s):// address:
    • the page's own scripts become <deck>/assets/index-abc.js:1:2345, so a frame still says where in the bundle and reads the same on every machine;
    • any other address keeps its scheme and path and loses its host and port, such as https://<host>/v1/app/errors (a user in front of the host goes with it).
  • The path pass leaves the path after <deck> or <host> alone, so scrubbing twice changes nothing.
  • README and PRODUCT.md say machine names in addresses are scrubbed out too.

The API's second scrub applies the same rule already, so reports from older versions are stored without the host too.

Verification

  • npm run typecheck clean.
  • Full suite (npx vitest run --maxWorkers=3 --minWorkers=1): 890 files, 11676 tests passed.
  • New src/web/__tests__/error-report-origins.test.ts: 17 address shapes through both scrubs (Chrome, Firefox and Safari frames; hostname, loopback, IPv6 and LAN addresses; a dynamic-import failure; other hosts, a proxy with a user, a WebSocket, a blob URL, an already-scrubbed line), the pattern held equal between the two copies, and an error posted to /api/client-error with a stubbed fetch, asserting the report carries neither the host nor the port. Before the change all 31 behavioural cases failed with the host still in the output.
  • error-report-paths.test.ts: the address lines that used to be kept verbatim moved to the new test, where they keep their path under <deck>; the drift test between the two copies stays green.

A deck opened from another machine is opened by that machine's name,
and every frame of a page error carried it to the report
(http://alices-macbook.local:4317/assets/index-abc.js:1:2345). Both
scrubs now replace the host of every http(s) and ws(s) address: the
page's own scripts become <deck>/assets/index-abc.js:1:2345, so a
frame still says where in the bundle, and any other address keeps its
scheme and path as https://<host>/... The path pass leaves the path
after either placeholder alone, so scrubbing twice changes nothing.
@BarganConstantin
BarganConstantin merged commit 365f971 into development Oct 4, 2026
10 checks passed
@BarganConstantin BarganConstantin mentioned this pull request Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant