feat(server): enhance secret management and logging functionality
- Added SCRUNNER_SECRETS_KEY to README as a required variable for production. - Implemented redaction of sensitive information in logs across various components. - Enhanced script execution functions to include an owner parameter for better secret management. - Introduced a secrets API in the script sandbox for retrieving and managing secrets. - Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
@@ -3,6 +3,18 @@ import path from "path";
|
||||
import pino from "pino";
|
||||
import * as store from "./store.js";
|
||||
import { LOGS_DIR } from "./paths.js";
|
||||
import { redactString } from "./secret-value.js";
|
||||
|
||||
/**
|
||||
* @param {{ write: (line: string) => unknown }} dest
|
||||
*/
|
||||
function redactStream(dest) {
|
||||
return {
|
||||
write(line) {
|
||||
dest.write(redactString(typeof line === "string" ? line : String(line)));
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
const LEVEL_TO_NUM = {
|
||||
trace: 10,
|
||||
@@ -27,7 +39,7 @@ let timer = null;
|
||||
function enqueueLine(line) {
|
||||
let record;
|
||||
try {
|
||||
record = JSON.parse(line);
|
||||
record = JSON.parse(redactString(line));
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
@@ -103,9 +115,9 @@ const rollingFile = pino.transport({
|
||||
export const log = pino(
|
||||
{ level: process.env.SCRUNNER_LOG_LEVEL ?? "debug" },
|
||||
pino.multistream([
|
||||
{ level: "debug", stream: process.stdout },
|
||||
{ level: "debug", stream: rollingFile },
|
||||
{ level: "debug", stream: sqliteStream },
|
||||
{ level: "debug", stream: redactStream(process.stdout) },
|
||||
{ level: "debug", stream: redactStream(rollingFile) },
|
||||
{ level: "debug", stream: redactStream(sqliteStream) },
|
||||
]),
|
||||
);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user