From da8f424eb055ea35f72fea0afd460d4fd3a5ae18 Mon Sep 17 00:00:00 2001 From: kdletters <61648117+kdletters@users.noreply.github.com> Date: Mon, 5 Oct 2026 11:03:46 +0800 Subject: [PATCH] =?UTF-8?q?=E8=84=B1=E6=95=8F=E5=AE=A2=E6=88=B7=E7=AB=AF?= =?UTF-8?q?=E9=94=99=E8=AF=AF=E4=B8=8A=E6=8A=A5=E6=AD=A3=E6=96=87?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 错误池消息与 stack 统一隐藏凭据、URL、路径和长标识 补充错误上报敏感正文回归 --- .../src/services/errorReporting.ts | 8 +++++-- .../tests/errorReporting.test.ts | 22 ++++++++++++++++++- 2 files changed, 27 insertions(+), 3 deletions(-) diff --git a/apps/ai-game-creator-shell/src/services/errorReporting.ts b/apps/ai-game-creator-shell/src/services/errorReporting.ts index 08d8d53da..7e7368b66 100644 --- a/apps/ai-game-creator-shell/src/services/errorReporting.ts +++ b/apps/ai-game-creator-shell/src/services/errorReporting.ts @@ -106,8 +106,12 @@ export async function captureClientError( } else { errorValue = new Error(String(error)); } - const message = errorValue.message || '未知客户端错误'; - const stack = errorValue.stack?.slice(0, 8_000); + const message = + normalizeDiagnosticText(errorValue.message || '').slice(0, 400) || + '未知客户端错误'; + const stack = errorValue.stack + ? normalizeDiagnosticText(errorValue.stack).slice(0, 8_000) + : undefined; return reportClientError({ source: context.source ?? 'client', message, diff --git a/apps/ai-game-creator-shell/tests/errorReporting.test.ts b/apps/ai-game-creator-shell/tests/errorReporting.test.ts index 104ea9fc0..707d99f9a 100644 --- a/apps/ai-game-creator-shell/tests/errorReporting.test.ts +++ b/apps/ai-game-creator-shell/tests/errorReporting.test.ts @@ -122,6 +122,26 @@ describe('客户端错误报告池', () => { }); }); + it('错误池保留状态和正文但不携带凭据、URL 或本地路径', async () => { + await captureClientError( + new Error( + 'HTTP 502 upstream overloaded;Authorization: Bearer fixture-secret;https://provider.example/private C:\\Users\\demo\\game', + ), + { source: 'test' }, + ); + + const [, args] = + vi + .mocked(invoke) + .mock.calls.find(([command]) => command === 'report_client_error') ?? + []; + const serialized = JSON.stringify(args); + expect(serialized).toContain('HTTP 502 upstream overloaded'); + expect(serialized).not.toContain('fixture-secret'); + expect(serialized).not.toContain('provider.example'); + expect(serialized).not.toContain('C:\\Users\\demo'); + }); + it('限制当前进程错误池最多保留 100 条', async () => { for (let index = 0; index < 101; index += 1) { await captureClientError(new Error(`错误 ${index}`), { source: 'test' }); @@ -243,7 +263,7 @@ describe('客户端错误报告池', () => { expect(invoke).toHaveBeenCalledWith('report_client_error', { source: 'unhandledrejection', message: 'IPC 桥接异常', - stack: original.stack, + stack: normalizeDiagnosticText(original.stack ?? ''), action: undefined, page: undefined, });