Skip to content

[Observability] Verify telemetry redaction at feature boundaries - #165

Merged
BigDella merged 3 commits into
Parcel-Protocol:mainfrom
bamiebot-maker:feat/151-telemetry-feature-boundary-redaction
Sep 27, 2026
Merged

BigDella merged 3 commits into
Parcel-Protocol:mainfrom
bamiebot-maker:feat/151-telemetry-feature-boundary-redaction

Conversation

@bamiebot-maker

Copy link
Copy Markdown
Contributor

[Observability] Verify telemetry redaction at feature boundaries

Closes #151

Summary of Changes

This pull request adds integration tests and hardening for telemetry redaction at feature boundaries, verifying that feature-level failures emit correlation metadata without leaking account secrets, full addresses where disallowed, or raw HTTP bodies:

  1. Telemetry Capture Integration in Network Profile Test Runner:

    • Integrated TelemetryCaptureSink into runAgainstNetworkProfiles in core/testing/runAgainstProfiles.ts.
    • Bound sink lifecycle (beforeEach(() => { telemetry.clear(); setTelemetrySink(telemetry); }) and afterEach(() => { resetTelemetrySink(); })).
    • Extended NetworkProfileContext in core/testing/networkProfiles.ts to provide telemetry for profile-driven integration tests.
  2. Boundary Redaction Hardening:

    • Updated isSensitiveKey in core/telemetry/telemetry.ts to redact raw HTTP body keys (rawBody, responseBody, requestBody, httpBody, body, raw_body, etc.) and disallowed address keys (disallowedAddress, forbiddenAddress).
    • Enhanced emitTelemetry to scrub errorCode before emission, ensuring callers preformatting error codes with secret strings or seeds are safely scrubbed.
    • Refined EMBEDDED_STELLAR_SECRET pattern (/[SM][A-Z2-7]{55}/g) and bearer token pattern to match embedded secrets regardless of prefix/suffix word boundaries.
    • Added RedactOptions supporting { redactAddresses: true } to redact Stellar public addresses (/[GC][A-Z2-7]{55}/g) when address redaction is mandated.
  3. Feature Boundary Integration Test Suite:

    • Added core/telemetry/__tests__/featureBoundaries.test.ts with 9 focused tests:
      • Verifying preservation of required correlation metadata (op, actorType, result, latencyMs, correlationId, errorCode, timestamp) on failure.
      • Verifying scrubbing of callers preformatting error strings containing secret seeds, bearer tokens, and raw HTTP bodies.
      • Verifying redaction of raw HTTP response bodies and disallowed address fields in feature payloads while preserving allowed public account identifiers in non-sensitive context.
      • Verifying address redaction when explicitly configured via RedactOptions.
      • Verifying actual feature request and error execution paths (Horizon timeouts and AbortController cancellations via runHorizonRequest).
      • Verifying export workflow authorization failure (exportRecords) with capture sink.
      • Verifying cross-network profile integration (runAgainstNetworkProfiles) capturing Horizon requests and confirming absence of raw account bodies.

Verification

  • npx vitest run core/telemetry (All 21 tests passing across telemetry.test.ts and featureBoundaries.test.ts)
  • npx vitest run core/testing/__tests__/networkProfiles.test.ts (All 39 tests passing)
  • npm run verify:telemetry (All 11 instrumented operations OK)
  • npm run verify:audit (9 sensitive actions, 9 domain-boundary emitters OK)
  • npm run verify:boundaries (OK: feature slices import boundaries clean)
  • npm run verify:issues (OK)

@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@bamiebot-maker Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@BigDella
BigDella merged commit 698c5c6 into Parcel-Protocol:main Sep 27, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Observability] Verify telemetry redaction at feature boundaries

2 participants