Summary
testCallHistory.saveEntry stores full response bodies and requestParams in localStorage (up to 50 entries) with no redaction or expiry.
Why this matters
Responses often include tokens or PII; persisting them indefinitely in localStorage exposes them to any script on the origin.
Scope
Run requestParams and stringified responses through redactSensitiveData before saving, cap stored body size, and add an age-based purge (e.g. 7 days).
Relevant code in CalloraOrg/Callora-Frontend:
src/state/testCallHistory.ts
src/services/SecureErrorHandler.ts
Priority
Medium
Acceptance criteria
- Stored entries have secrets redacted
- Response bodies above the cap are truncated
- Entries older than the retention window are purged on load
- Tests cover redaction and purge
Validation
npm test -- --run src/state/testCallHistory.test.ts
Non-goals
- Typo-only, formatting-only, or cosmetic changes.
- Unrelated refactors, dependency upgrades, or broad rewrites.
- Removing safeguards or weakening validation to make tests pass.
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.
Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code
Summary
testCallHistory.saveEntry stores full response bodies and requestParams in localStorage (up to 50 entries) with no redaction or expiry.
Why this matters
Responses often include tokens or PII; persisting them indefinitely in localStorage exposes them to any script on the origin.
Scope
Run requestParams and stringified responses through redactSensitiveData before saving, cap stored body size, and add an age-based purge (e.g. 7 days).
Relevant code in CalloraOrg/Callora-Frontend:
src/state/testCallHistory.tssrc/services/SecureErrorHandler.tsPriority
Medium
Acceptance criteria
Validation
npm test -- --run src/state/testCallHistory.test.ts
Non-goals
Contributor application
Before coding, describe the affected modules, proposed state/invariant changes, test strategy, compatibility considerations, and an estimate. Wait for assignment before starting implementation.
PR requirements
Use a feature branch and include
Closes #<issue-number>. Address every criterion, map criteria to code and tests, explain security and failure-mode handling, and ensure CI passes.Quality review
A maintainer will assess correctness, completeness, test depth, compatibility, observability, and adverse-case handling. A substantive implementation is required; merge or CI status alone does not guarantee reward eligibility.
Generated by Claude Code