Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 30 additions & 5 deletions src/ast/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -763,7 +763,7 @@ impl Location {
}

pub fn init_or_null(_source: Option<&Source>, r: Range) -> Option<Location> {
Self::init_or_null_impl(_source, r, None)
Self::init_or_null_impl(_source, r, None, false)
}

/// `init_or_null`, but computing the line/column through a
Expand All @@ -773,14 +773,16 @@ impl Location {
_source: Option<&Source>,
r: Range,
tracker: &mut LineColumnTracker,
redact_sensitive_information: bool,
) -> Option<Location> {
Self::init_or_null_impl(_source, r, Some(tracker))
Self::init_or_null_impl(_source, r, Some(tracker), redact_sensitive_information)
}

fn init_or_null_impl(
_source: Option<&Source>,
r: Range,
tracker: Option<&mut LineColumnTracker>,
redact_sensitive_information: bool,
) -> Option<Location> {
if let Some(source) = _source {
if r.is_empty() {
Expand All @@ -798,7 +800,18 @@ impl Location {
Some(tracker) => tracker.error_position(source, r.loc),
None => source.init_error_position(r.loc),
};
let mut full_line = &source.contents[data.line_start..data.line_end];
// Mask before the window: it can cut away the key that marks a secret.
let masked: Cow<'_, [u8]> = if redact_sensitive_information {
alloc_print(format_args!(
"{}",
bun_core::fmt::redacted_source(
&source.contents[data.line_start..data.line_end]
)
))
Comment thread
robobun marked this conversation as resolved.
} else {
Cow::Borrowed(&source.contents[data.line_start..data.line_end])
};
let mut full_line: &[u8] = &masked;
// Window a long line to ~120 bytes around the error. Bounds are
// BYTE offsets; the gate keeps the original shape (no left trim for
// an error in the last 80 bytes) so `write_format`'s caret aligns.
Expand Down Expand Up @@ -1472,12 +1485,23 @@ impl Log {
source: Option<&Source>,
r: Range,
text: impl IntoText,
) -> Data {
self.tracked_range_data_with(source, r, text, false)
}

fn tracked_range_data_with(
&mut self,
source: Option<&Source>,
r: Range,
text: impl IntoText,
redact_sensitive_information: bool,
) -> Data {
let location = if source.is_some() {
Location::init_or_null_tracked(
source,
r,
self.line_column_tracker.get_or_insert_default(),
redact_sensitive_information,
)
} else {
Location::init_or_null(source, r)
Expand Down Expand Up @@ -1631,7 +1655,7 @@ impl Log {
_ => {}
}
let data = self
.tracked_range_data(source, r, text)
.tracked_range_data_with(source, r, text, redact_sensitive_information)
.clone_line_text(self.clone_line_text);
self.add_msg(Msg {
kind,
Expand Down Expand Up @@ -2120,13 +2144,14 @@ impl Log {
#[cold]
pub fn add_error_opts(&mut self, text: Str, opts: AddErrorOptions<'_>) {
self.errors += 1;
let data = self.tracked_range_data(
let data = self.tracked_range_data_with(
opts.source,
Range {
loc: opts.loc,
len: opts.len,
},
text,
opts.redact_sensitive_information,
);
self.add_msg(Msg {
kind: Kind::Err,
Expand Down
2 changes: 1 addition & 1 deletion src/bun_core/fmt.rs
Original file line number Diff line number Diff line change
Expand Up @@ -332,7 +332,7 @@ impl Display for RedactedSourceFormatter<'_> {
}
}

pub(crate) fn redacted_source(str: &[u8]) -> RedactedSourceFormatter<'_> {
pub fn redacted_source(str: &[u8]) -> RedactedSourceFormatter<'_> {
RedactedSourceFormatter { text: str }
}

Expand Down
50 changes: 50 additions & 0 deletions test/cli/install/redacted-config-logs.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,56 @@ test("bunfig password value is masked in config error output", async () => {
expect(coloredExit).toBe(1);
});

describe.concurrent("bunfig token value is masked when the error is on a long line", () => {
// The key is more than 40 bytes before the error and more than 80 bytes
// follow it, so the printed excerpt starts inside the secret.
const secret = Buffer.alloc(72, "SECRET").toString();
const cases = [
{
title: "toml syntax error",
bunfig: `[install]\ntoken = "${secret}" ] # ${Buffer.alloc(120, "x").toString()}\n`,
excerpt: /^2 \| \*+" \] # x+$/m,
error: "Expected a newline or end of file after a key/value pair",
},
{
title: "bunfig validation error",
bunfig: `install = { registry = { token = "${secret}" }, cafile = 1, ca = "${Buffer.alloc(90, "x").toString()}" }\n`,
excerpt: /^1 \| \*+" }, cafile = 1, ca = "x+$/m,
error: "Invalid cafile. Expected a string.",
},
];

for (const { title, bunfig, excerpt, error } of cases) {
test(title, async () => {
using dir = tempDir("redacted-bunfig-long-line", {
"bunfig.toml": bunfig,
"package.json": "{}",
});

for (const env of [
{ ...bunEnv, NO_COLOR: "1" },
{ ...bunEnv, NO_COLOR: undefined, FORCE_COLOR: "1" },
]) {
await using proc = Bun.spawn({
cmd: [bunExe(), "install"],
cwd: String(dir),
env,
stdout: "pipe",
stderr: "pipe",
});

const [out, err, exitCode] = await Promise.all([proc.stdout.text(), proc.stderr.text(), proc.exited]);

expect(out).not.toContain("SECRET");
expect(err).not.toContain("SECRET");
expect(Bun.stripANSI(err)).toMatch(excerpt);
expect(err).toContain(error);
expect(exitCode).toBe(1);
}
});
}
});

describe.concurrent("redact", async () => {
const tests = [
{
Expand Down
Loading