Skip to content

fix(security): scrub every serialized event string - #262

Draft
rabesss wants to merge 1 commit into
mainfrom
dot/fix-254-event-strings
Draft

rabesss wants to merge 1 commit into
mainfrom
dot/fix-254-event-strings

Conversation

@rabesss

@rabesss rabesss commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes #254.

Scrub decoded JSON strings and keys at the event serialization boundary, after standard JSON marshaling. Covers nested artifacts, maps, typed Details and custom marshalers without mutating caller-owned data or changing numeric precision, benign JSON bytes, or serialization/terminal error behavior. Documents the boundary; no shared secrets-parser changes.

Validation

  • Original regression reproduced before fix
  • Events tests and race tests pass, including repeated independent race runs
  • CLI/watch ordinary and race integration checks pass
  • Full vet, golangci-lint v2.12.1 (0 issues), and build with -buildvcs=false pass
  • Independent review found no issues

Full go test ./... was attempted and retains the clean-main sandbox failures: network-dependent client tests and nine player AF_UNIX socket tests. Worktree builds require -buildvcs=false because of the environment's VCS lookup. Hosted CI and Security passed on the final head: https://github.com/rabesss/impartus-cli/actions/runs/37479466827. The latest title check also passes.

@rabesss
rabesss force-pushed the dot/fix-254-event-strings branch from c96a188 to ed073cb Compare October 6, 2026 14:29
@rabesss rabesss changed the title fix(events): scrub every serialized event string fix(security): scrub every serialized event string Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(events): scrub every string field in Writer.Emit, not only Error

1 participant