fix(api-tester): sanitize auth credentials and prevent plaintext localStorage persistence - #91
Conversation
…lStorage persistence - Exclude bearer tokens, basic auth credentials, and Authorization headers from localStorage persistence - Add automatic legacy unencrypted credentials migration and storage scrubbing on mount - Add prominent security & privacy alert banner to Save Workflow modal with optional tab-only sessionStorage toggle - Add 'Forget Credentials' action in builder Auth tab and 'Forget Stored Credentials' in Workflows tab - Add 'Clear History' action in Request History tab - Mark saved workflows requiring credentials with an Auth Required badge - Sanitize workflow export JSON and import inputs - Add comprehensive unit test suite in curlSecurity.test.ts Closes #72
✅ Deploy Preview for toolglass-by-ajithakdev ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
Devin Review found 3 potential issues.
2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)
| if (saveToSession && hasCreds) { | ||
| saveSessionAuth(newId, { | ||
| bearerToken: currentConfig.bearerToken, | ||
| basicUser: currentConfig.basicUser, | ||
| basicPass: currentConfig.basicPass | ||
| }); |
There was a problem hiding this comment.
🟡 Header-authenticated workflows lose credentials
For sensitive-header authentication, saveSessionAuth omits the header even when tab retention is selected. sanitizeSavedRequest removes it permanently. Quick Run then sends the request without its required credential.
Prompt for agents
Extend tab-only workflow credentials to support sensitive request headers. The save paths in src/tools/curl-to-fetch/CurlTool.tsx detect these headers as credentials, but SessionAuthData and saveSessionAuth in curlSecurity.ts retain only bearerToken, basicUser, and basicPass. Saved workflows strip sensitive headers, and handleQuickRun filters them again. Preserve opted-in sensitive headers in sessionStorage and reconstruct them only for the matching workflow during load and Quick Run. Add tests covering authType none with Authorization, X-API-KEY, and Cookie headers.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if (saveToSession && hasCreds) { | ||
| saveSessionAuth(editingWorkflowId, { | ||
| bearerToken: currentConfig.bearerToken, | ||
| basicUser: currentConfig.basicUser, | ||
| basicPass: currentConfig.basicPass | ||
| }); |
There was a problem hiding this comment.
🟡 Metadata edits cross-wire credentials
Saving an edited workflow with tab retention stores the active builder's credentials under editingWorkflowId. The metadata edit never loads that workflow. Quick Run then uses unrelated credentials.
Prompt for agents
Separate metadata-only editing from credential retention in src/tools/curl-to-fetch/CurlTool.tsx. handleEditWorkflow does not load the selected workflow, so getCurrentRequestConfig describes whichever request is currently in the builder. Do not save that configuration's credentials under editingWorkflowId from handleSaveRequest. Credential retention for an existing workflow must use credentials explicitly associated with that workflow, such as during the Apply configuration action or after loading it into the builder. Add a UI test that edits workflow A while workflow B is active.
Was this helpful? React with 👍 or 👎 to provide feedback.
| const filtered = prev.filter(h => !isSensitiveHeader(h.key)); | ||
| return filtered.length > 0 ? filtered : [{ key: '', value: '' }]; | ||
| }); | ||
| clearSessionAuth(); |
There was a problem hiding this comment.
🟡 Active forget clears every workflow
handleForgetActiveCredentials calls clearSessionAuth without an ID, deleting credentials remembered for every workflow. Forgetting one request forces re-entry across the entire tab.
Prompt for agents
Make the Builder's active-credential action clear only credentials associated with the loaded workflow, while still clearing the visible React credential fields and sensitive headers. Track the loaded workflow ID or avoid deleting sessionStorage when the active request has no workflow association. Preserve clearSessionAuth() without an ID for the separate Forget Stored Credentials action. Add a test with two remembered workflows proving that forgetting one leaves the other intact.
Was this helpful? React with 👍 or 👎 to provide feedback.
Summary of Changes
Fixes and closes #72.
1. Zero Plaintext Auth Storage
basicUser,basicPass), and sensitive headers (Authorization,Proxy-Authorization,X-API-KEY, cookies) before saving workflows or history items tolocalStorage.2. Automatic Legacy Storage Scrubbing / Migration
scrubStorageAuth()scanslocalStoragefor any pre-existing unencrypted auth data from earlier versions of Toolglass, cleanses the stored records in place, and alerts the user with a privacy protection toast.3. Security Warning & In-Tab Session Storage
sessionStorageretention (auto-cleared when the browser tab is closed) for testing convenience without risking permanent disk persistence.4. 'Forget Credentials' & Management Controls
🔒 AUTH REQUIREDbadge.5. Tests & Verification
src/tools/curl-to-fetch/curlSecurity.test.ts(13 tests, 100% passing).