脱敏客户端错误上报正文

错误池消息与 stack 统一隐藏凭据、URL、路径和长标识

补充错误上报敏感正文回归
This commit is contained in:
kdletters
2026-10-05 11:03:46 +08:00
parent b3a0f16b9c
commit da8f424eb0
2 changed files with 27 additions and 3 deletions
@@ -106,8 +106,12 @@ export async function captureClientError(
} else {
errorValue = new Error(String(error));
}
const message = errorValue.message || '未知客户端错误';
const stack = errorValue.stack?.slice(0, 8_000);
const message =
normalizeDiagnosticText(errorValue.message || '').slice(0, 400) ||
'未知客户端错误';
const stack = errorValue.stack
? normalizeDiagnosticText(errorValue.stack).slice(0, 8_000)
: undefined;
return reportClientError({
source: context.source ?? 'client',
message,
@@ -122,6 +122,26 @@ describe('客户端错误报告池', () => {
});
});
it('错误池保留状态和正文但不携带凭据、URL 或本地路径', async () => {
await captureClientError(
new Error(
'HTTP 502 upstream overloaded;Authorization: Bearer fixture-secret;https://provider.example/private C:\\Users\\demo\\game',
),
{ source: 'test' },
);
const [, args] =
vi
.mocked(invoke)
.mock.calls.find(([command]) => command === 'report_client_error') ??
[];
const serialized = JSON.stringify(args);
expect(serialized).toContain('HTTP 502 upstream overloaded');
expect(serialized).not.toContain('fixture-secret');
expect(serialized).not.toContain('provider.example');
expect(serialized).not.toContain('C:\\Users\\demo');
});
it('限制当前进程错误池最多保留 100 条', async () => {
for (let index = 0; index < 101; index += 1) {
await captureClientError(new Error(`错误 ${index}`), { source: 'test' });
@@ -243,7 +263,7 @@ describe('客户端错误报告池', () => {
expect(invoke).toHaveBeenCalledWith('report_client_error', {
source: 'unhandledrejection',
message: 'IPC 桥接异常',
stack: original.stack,
stack: normalizeDiagnosticText(original.stack ?? ''),
action: undefined,
page: undefined,
});