Skip to content

fix: serialize RegExp redact patterns across the nuxt and nitro config bridges - #794

Merged
HugoRCD merged 1 commit into
mainfrom
EVL-516/fix-regexp-redact-patterns-bridge
Oct 9, 2026
Merged

HugoRCD merged 1 commit into
mainfrom
EVL-516/fix-regexp-redact-patterns-bridge

Conversation

@evlogai

@evlogai evlogai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Closes #736 · Linear EVL-516

The bug

A RegExp in redact.patterns declared in nuxt.config.ts never reached the server. The Nuxt module and both standalone Nitro modules pass user options through JSON.stringify (the __EVLOG_CONFIG__ bridge and process.env.__EVLOG_CONFIG), and a RegExp serializes to {}. deserializeRegexList then skips the entry silently, because its console.warn only covers the catch path. The custom patterns never apply and the value goes out unredacted.

The fix

prepareRedactForBridge(redact) in packages/evlog/src/redact.ts:

  • rewrites RegExp patterns in place to { source, flags } — the shape deserializeRegexList already reads back — before the options land in a runtimeConfig or a JSON bridge;
  • carries the function-valued redact policy warning (FUNCTION_REDACT_POLICY_WARNING), which the Nuxt module was missing: a redact.replacement / redact.transform function in nuxt.config.ts now fails loudly like it already did in the standalone Nitro modules.

It is called from all three modules (nuxt/module.ts, nitro/module.ts, nitro-v3/module.ts) before runtimeConfig assignment and the JSON.stringify bridges, so the runtimeConfig.evlog path is covered too — that path receives the raw options and the server plugin prefers it over the env bridge.

deserializeRegexList now warns on a pattern object without a source field instead of dropping it silently.

Before / after (regression test, test/core/redact.test.ts)

Fails on main, passes with the fix (verified: 4 new tests fail pre-fix, 78/78 pass post-fix):

const redact = { builtins: false, patterns: [/sk_live_\w+/g] }
prepareRedactForBridge(redact)
const serialized = JSON.parse(JSON.stringify(redact))
const resolved = normalizeRedactConfig(serialized)
redactEvent({ key: 'sk_live_abc123' }, resolved)
// before: { key: 'sk_live_abc123' }   — pattern dropped as {}
// after:  { key: '[REDACTED]' }

Reproducing the issue's repro directly on main: JSON.stringify({ patterns: [/SECRET_\w+/g] }) → {"patterns":[{}]}; with the bridge helper → {"patterns":[{"source":"SECRET_\\w+","flags":"g"}]}.

Smaller items from the issue, also here

  • ModuleOptions.retention JSDoc default corrected '30d' → '7d', matching @evlog/nuxthub and the NuxtHub docs page.
  • EvlogConfig JSDoc in packages/evlog/src/shared/define.ts: dropped the stale "in the Nuxt module" claim (Nuxt ModuleOptions doesn't take an EvlogConfig, and its function fields wouldn't survive the JSON bridge).
  • FeatureSampling.vue: the initLogger({...}) snippet is no longer labelled evlog.config.ts (nothing auto-loads such a file); relabelled logger.ts.
  • packages/signals/README.md: the defineEvlog({ plugins: [...] }) snippet now says the config registers nothing until it is passed to initLogger or the framework integration.

Not addressed here

  • The map.ignore limitation on the unmerged feat/evlog-config branch (inline routes can't be ignored one by one): noted as a decision for that PR or for the /cli/config page, per the issue.

Checks

  • pnpm run lint, pnpm run typecheck, pnpm run test: all pass on this branch (sandbox run, remote cache read-only; revision 099ee52).
  • Regression test written first and confirmed failing against the unfixed source.
  • Changeset included (evlog: patch). The FeatureSampling.vue label swap is a rendered docs change; the pixel diff is one word in a decorative editor header, so no before/after capture was produced for it.
ELI5

When you write custom secret-hiding rules in your Nuxt config, they were thrown away without any warning because of how those rules travel from the config file into the running server: the trip only understands plain data, and a RegExp turns into an empty shell on the way. The rules now travel in a form the server can rebuild, and anything that still can't make the trip gets announced instead of quietly ignored.

…g bridges

A RegExp in redact.patterns serializes to {} under JSON.stringify, so
custom patterns declared in nuxt.config.ts or Nitro module options never
reached the server. prepareRedactForBridge rewrites them in place to
{ source, flags } — the shape deserializeRegexList reads back — before
the options land in a runtimeConfig or a JSON bridge, and covers the
function-valued redact policy warning the Nuxt module was missing.
deserializeRegexList now reports pattern objects without a source field
instead of skipping them silently.

Also corrects stale config docs: the ModuleOptions.retention default
(@evlog/nuxthub uses '7d'), the EvlogConfig JSDoc, the sampling feature
snippet labelled evlog.config.ts, and the signals README registration
note.
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
evi Ready Ready Preview Oct 8, 2026 10:52pm UTC
evlog-docs Ready Ready Preview, v0 Oct 8, 2026 10:52pm UTC
evlog-render-lab Ready Ready Preview Oct 8, 2026 10:52pm UTC
evlog-telemetry Ready Ready Preview Oct 8, 2026 10:52pm UTC
just-use-evlog Ready Ready Preview Oct 8, 2026 10:52pm UTC

Request Review

@evlogai
evlogai Bot requested a review from HugoRCD October 8, 2026 22:47
@github-actions github-actions Bot added the bug Something isn't working label Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2b9519d7-c0c5-465d-8569-1df7eb22aa4e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thank you for following the naming conventions! 🙏

@pkg-pr-new

pkg-pr-new Bot commented Oct 8, 2026

Copy link
Copy Markdown
@evlog/cli

npm i https://pkg.pr.new/@evlog/cli@794

evlog

npm i https://pkg.pr.new/evlog@794

@evlog/nuxthub

npm i https://pkg.pr.new/@evlog/nuxthub@794

@evlog/signals

npm i https://pkg.pr.new/@evlog/signals@794

@evlog/telemetry

npm i https://pkg.pr.new/@evlog/telemetry@794

commit: 099ee52

@HugoRCD
HugoRCD merged commit bd3558d into main Oct 9, 2026
20 checks passed
@HugoRCD
HugoRCD deleted the EVL-516/fix-regexp-redact-patterns-bridge branch October 9, 2026 20:20

This branch was successfully deployed

5 active deployments
Preview – evlog-docs — 099ee527 Deployed Oct 8, 2026 by vercel[bot]
Preview – evlog-telemetry — 099ee527 Deployed Oct 8, 2026 by vercel[bot]
Preview – evi — 099ee527 Deployed Oct 8, 2026 by vercel[bot]
Preview – just-use-evlog — 099ee527 Deployed Oct 8, 2026 by vercel[bot]
Preview – evlog-render-lab — 099ee527 Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant