Skip to content

Design crash-reporting guardrails before any crash reporter is integrated #27

Description

@ndii-dev

There is no Sentry/Bugsnag/etc. integration yet — but given the eventual need for one, and that this codebase handles a live Stellar secret in memory during signing, retroactively bolting on PII/secret scrubbing after a reporter ships is how leaks happen. Specify the guardrail architecture now: an allowlist-based breadcrumb/context filter (not a denylist, which always misses a field eventually), and a lint rule or code-review checklist item blocking any crash-reporter setContext/setExtra call outside the vetted wrapper.

Definition of done:

  • Written policy: allowlist approach specified, denylist approach explicitly rejected with rationale
  • A wrapper module that is the only sanctioned way to attach context to error reports, reviewed for secret-safety
  • A test that asserts a payload containing something matching a Stellar-secret-shaped string (S + 55 base32 chars) is never present in any reporter payload the wrapper produces

Before opening a PR for this issue, read CONTRIBUTING.md.

This is not a starter-issue. The Definition of done above is the full
acceptance criteria, not a subset to sample from — a PR that addresses part
of it is an unfinished issue, not a smaller one. Your PR must include, in
the PR description itself:

  • Root cause / design-decision rationale in your own words — not a restatement of this issue
  • Every Definition of done bullet above addressed explicitly, with a one-line note on how
  • Evidence the code actually runs: pasted test/build output, a screen recording or before/after screenshots for UI changes, or real (non-mocked) logs for network/contract-facing work
  • New or updated tests included and shown passing (paste the output)
  • Any adjacent/related behavior this issue calls out re-verified, not assumed unaffected

PRs missing these will be sent back before review, not reviewed and rejected — please do this up front.

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSMaybe RewardedIssue may be eligible for a GrantFox rewardOfficial Campaign | FWC26Campaign: Official Campaign | FWC26

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions