Repository navigation
fix: serialize RegExp redact patterns across the nuxt and nitro config bridges - #794
Merged
Merged
Conversation
…g bridges
A RegExp in redact.patterns serializes to {} under JSON.stringify, so
custom patterns declared in nuxt.config.ts or Nitro module options never
reached the server. prepareRedactForBridge rewrites them in place to
{ source, flags } — the shape deserializeRegexList reads back — before
the options land in a runtimeConfig or a JSON bridge, and covers the
function-valued redact policy warning the Nuxt module was missing.
deserializeRegexList now reports pattern objects without a source field
instead of skipping them silently.
Also corrects stale config docs: the ModuleOptions.retention default
(@evlog/nuxthub uses '7d'), the EvlogConfig JSDoc, the sampling feature
snippet labelled evlog.config.ts, and the signals README registration
note.
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
Thank you for following the naming conventions! 🙏 |
@evlog/cli
evlog
@evlog/nuxthub
@evlog/signals
@evlog/telemetry
commit: |
This was referenced Oct 9, 2026
1 of 2 tasks
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #736 · Linear EVL-516
The bug
A RegExp in
redact.patternsdeclared innuxt.config.tsnever reached the server. The Nuxt module and both standalone Nitro modules pass user options throughJSON.stringify(the__EVLOG_CONFIG__bridge andprocess.env.__EVLOG_CONFIG), and a RegExp serializes to{}.deserializeRegexListthen skips the entry silently, because itsconsole.warnonly covers thecatchpath. The custom patterns never apply and the value goes out unredacted.The fix
prepareRedactForBridge(redact)inpackages/evlog/src/redact.ts:{ source, flags }— the shapedeserializeRegexListalready reads back — before the options land in a runtimeConfig or a JSON bridge;FUNCTION_REDACT_POLICY_WARNING), which the Nuxt module was missing: aredact.replacement/redact.transformfunction innuxt.config.tsnow fails loudly like it already did in the standalone Nitro modules.It is called from all three modules (
nuxt/module.ts,nitro/module.ts,nitro-v3/module.ts) beforeruntimeConfigassignment and theJSON.stringifybridges, so theruntimeConfig.evlogpath is covered too — that path receives the raw options and the server plugin prefers it over the env bridge.deserializeRegexListnow warns on a pattern object without asourcefield instead of dropping it silently.Before / after (regression test,
test/core/redact.test.ts)Fails on
main, passes with the fix (verified: 4 new tests fail pre-fix, 78/78 pass post-fix):Reproducing the issue's repro directly on
main:JSON.stringify({ patterns: [/SECRET_\w+/g] })→{"patterns":[{}]}; with the bridge helper →{"patterns":[{"source":"SECRET_\\w+","flags":"g"}]}.Smaller items from the issue, also here
ModuleOptions.retentionJSDoc default corrected'30d'→'7d', matching@evlog/nuxthuband the NuxtHub docs page.EvlogConfigJSDoc inpackages/evlog/src/shared/define.ts: dropped the stale "in the Nuxt module" claim (NuxtModuleOptionsdoesn't take anEvlogConfig, and its function fields wouldn't survive the JSON bridge).FeatureSampling.vue: theinitLogger({...})snippet is no longer labelledevlog.config.ts(nothing auto-loads such a file); relabelledlogger.ts.packages/signals/README.md: thedefineEvlog({ plugins: [...] })snippet now says the config registers nothing until it is passed toinitLoggeror the framework integration.Not addressed here
map.ignorelimitation on the unmergedfeat/evlog-configbranch (inline routes can't be ignored one by one): noted as a decision for that PR or for the/cli/configpage, per the issue.Checks
pnpm run lint,pnpm run typecheck,pnpm run test: all pass on this branch (sandbox run, remote cache read-only; revision099ee52).evlog: patch). TheFeatureSampling.vuelabel swap is a rendered docs change; the pixel diff is one word in a decorative editor header, so no before/after capture was produced for it.ELI5
When you write custom secret-hiding rules in your Nuxt config, they were thrown away without any warning because of how those rules travel from the config file into the running server: the trip only understands plain data, and a RegExp turns into an empty shell on the way. The rules now travel in a form the server can rebuild, and anything that still can't make the trip gets announced instead of quietly ignored.