feat(server): enhance secret management and logging functionality

- Added SCRUNNER_SECRETS_KEY to README as a required variable for production.
- Implemented redaction of sensitive information in logs across various components.
- Enhanced script execution functions to include an owner parameter for better secret management.
- Introduced a secrets API in the script sandbox for retrieving and managing secrets.
- Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
2026-08-14 22:11:03 +07:00
parent 94aa5b2efa
commit 3e4d5f443d
19 changed files with 886 additions and 39 deletions
+16 -4
View File
@@ -3,6 +3,18 @@ import path from "path";
import pino from "pino";
import * as store from "./store.js";
import { LOGS_DIR } from "./paths.js";
import { redactString } from "./secret-value.js";
/**
* @param {{ write: (line: string) => unknown }} dest
*/
function redactStream(dest) {
return {
write(line) {
dest.write(redactString(typeof line === "string" ? line : String(line)));
},
};
}
const LEVEL_TO_NUM = {
trace: 10,
@@ -27,7 +39,7 @@ let timer = null;
function enqueueLine(line) {
let record;
try {
record = JSON.parse(line);
record = JSON.parse(redactString(line));
} catch {
return;
}
@@ -103,9 +115,9 @@ const rollingFile = pino.transport({
export const log = pino(
{ level: process.env.SCRUNNER_LOG_LEVEL ?? "debug" },
pino.multistream([
{ level: "debug", stream: process.stdout },
{ level: "debug", stream: rollingFile },
{ level: "debug", stream: sqliteStream },
{ level: "debug", stream: redactStream(process.stdout) },
{ level: "debug", stream: redactStream(rollingFile) },
{ level: "debug", stream: redactStream(sqliteStream) },
]),
);