Skip to content

fix(api-tester): sanitize auth credentials and prevent plaintext localStorage persistence - #91

Merged
ajithakdev merged 1 commit into
mainfrom
fix/api-tester-security-credentials
Sep 6, 2026
Merged

ajithakdev merged 1 commit into
mainfrom
fix/api-tester-security-credentials

Conversation

@ajithakdev

@ajithakdev ajithakdev commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Summary of Changes

Fixes and closes #72.

1. Zero Plaintext Auth Storage

  • Strips bearer tokens, basic auth credentials (basicUser, basicPass), and sensitive headers (Authorization, Proxy-Authorization, X-API-KEY, cookies) before saving workflows or history items to localStorage.
  • Sanitizes JSON workflow exports and imports.

2. Automatic Legacy Storage Scrubbing / Migration

  • On mount, scrubStorageAuth() scans localStorage for any pre-existing unencrypted auth data from earlier versions of Toolglass, cleanses the stored records in place, and alerts the user with a privacy protection toast.

3. Security Warning & In-Tab Session Storage

  • Save Workflow modal displays a prominent glassmorphic privacy warning banner whenever the request contains auth credentials.
  • Users can optionally opt in to temporary sessionStorage retention (auto-cleared when the browser tab is closed) for testing convenience without risking permanent disk persistence.

4. 'Forget Credentials' & Management Controls

  • Added Forget Credentials action in the Builder's Authorization tab to instantly purge active tokens and credentials from memory and session.
  • Added Forget Stored Credentials action in the Workflows tab toolbar.
  • Added Clear History button in the Request History tab.
  • Saved workflow cards now display a dedicated 🔒 AUTH REQUIRED badge.
  • If Quick Run is triggered on a workflow requiring authentication without active credentials, execution is safely halted and the workflow is loaded into the builder with the Authorization tab focused.

5. Tests & Verification

  • Comprehensive test suite added in src/tools/curl-to-fetch/curlSecurity.test.ts (13 tests, 100% passing).
  • All 41 unit tests passing.
  • 0 ESLint warnings or errors.
  • Clean production build with TypeScript check passing.
  • End-to-end browser verification via Chromium completed with verified screenshots.

Devin Review

…lStorage persistence

- Exclude bearer tokens, basic auth credentials, and Authorization headers from localStorage persistence
- Add automatic legacy unencrypted credentials migration and storage scrubbing on mount
- Add prominent security & privacy alert banner to Save Workflow modal with optional tab-only sessionStorage toggle
- Add 'Forget Credentials' action in builder Auth tab and 'Forget Stored Credentials' in Workflows tab
- Add 'Clear History' action in Request History tab
- Mark saved workflows requiring credentials with an Auth Required badge
- Sanitize workflow export JSON and import inputs
- Add comprehensive unit test suite in curlSecurity.test.ts

Closes #72
@netlify

netlify Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for toolglass-by-ajithakdev ready!

Name Link
🔨 Latest commit bb8bb66
🔍 Latest deploy log https://app.netlify.com/projects/toolglass-by-ajithakdev/deploys/6a9d84e544fd88000887cc63
😎 Deploy Preview https://deploy-preview-91--toolglass-by-ajithakdev.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@ajithakdev
ajithakdev merged commit 89a0a2b into main Sep 6, 2026
6 of 7 checks passed

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)

Devin Review

Comment on lines +444 to +449
if (saveToSession && hasCreds) {
saveSessionAuth(newId, {
bearerToken: currentConfig.bearerToken,
basicUser: currentConfig.basicUser,
basicPass: currentConfig.basicPass
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Header-authenticated workflows lose credentials

For sensitive-header authentication, saveSessionAuth omits the header even when tab retention is selected. sanitizeSavedRequest removes it permanently. Quick Run then sends the request without its required credential.

Prompt for agents
Extend tab-only workflow credentials to support sensitive request headers. The save paths in src/tools/curl-to-fetch/CurlTool.tsx detect these headers as credentials, but SessionAuthData and saveSessionAuth in curlSecurity.ts retain only bearerToken, basicUser, and basicPass. Saved workflows strip sensitive headers, and handleQuickRun filters them again. Preserve opted-in sensitive headers in sessionStorage and reconstruct them only for the matching workflow during load and Quick Run. Add tests covering authType none with Authorization, X-API-KEY, and Cookie headers.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +420 to +425
if (saveToSession && hasCreds) {
saveSessionAuth(editingWorkflowId, {
bearerToken: currentConfig.bearerToken,
basicUser: currentConfig.basicUser,
basicPass: currentConfig.basicPass
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Metadata edits cross-wire credentials

Saving an edited workflow with tab retention stores the active builder's credentials under editingWorkflowId. The metadata edit never loads that workflow. Quick Run then uses unrelated credentials.

Prompt for agents
Separate metadata-only editing from credential retention in src/tools/curl-to-fetch/CurlTool.tsx. handleEditWorkflow does not load the selected workflow, so getCurrentRequestConfig describes whichever request is currently in the builder. Do not save that configuration's credentials under editingWorkflowId from handleSaveRequest. Credential retention for an existing workflow must use credentials explicitly associated with that workflow, such as during the Apply configuration action or after loading it into the builder. Add a UI test that edits workflow A while workflow B is active.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

const filtered = prev.filter(h => !isSensitiveHeader(h.key));
return filtered.length > 0 ? filtered : [{ key: '', value: '' }];
});
clearSessionAuth();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Active forget clears every workflow

handleForgetActiveCredentials calls clearSessionAuth without an ID, deleting credentials remembered for every workflow. Forgetting one request forces re-entry across the entire tab.

Prompt for agents
Make the Builder's active-credential action clear only credentials associated with the loaded workflow, while still clearing the visible React credential fields and sensitive headers. Track the loaded workflow ID or avoid deleting sessionStorage when the active request has no workflow association. Preserve clearSessionAuth() without an ID for the separate Forget Stored Credentials action. Add a test with two remembered workflows proving that forgetting one leaves the other intact.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@ajithakdev
ajithakdev deleted the fix/api-tester-security-credentials branch September 6, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: API Tester stores bearer tokens and credentials in localStorage unencrypted

1 participant