') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix(config): use redact on config output by lukekarrys · Pull Request #7521 · npm/cli · GitHub
Skip to content

fix(config): use redact on config output - #7521

Merged
lukekarrys merged 6 commits into
latestfrom
lk/protect-proxy
May 14, 2024
Merged

fix(config): use redact on config output#7521
lukekarrys merged 6 commits into
latestfrom
lk/protect-proxy

Conversation

@lukekarrys

Copy link
Copy Markdown
Contributor

Fixes#3867

@lukekarrys
lukekarrys requested a review from a team as a code ownerMay 13, 2024 22:41
@npm-cli-bot

npm-cli-bot commented May 13, 2024

Copy link
Copy Markdown
Collaborator

no statistically significant performance changes detected

timing results
app-largecleanlock-onlycache-onlymodules-onlyno-lockno-cacheno-modulesno-cleanshow-versionrun-scriptcache-only
peer-deps
no-clean
audit
npm@latest33.889 ±1.1610.629 ±0.0311.739 ±0.031.555 ±0.001.549 ±0.001.285 ±0.018.234 ±0.001.296 ±0.010.139 ±0.000.167 ±0.0013.357 ±0.193.519 ±2.06
#752132.651 ±0.9210.619 ±0.0011.680 ±0.021.561 ±0.051.544 ±0.021.270 ±0.018.248 ±0.051.291 ±0.020.137 ±0.000.164 ±0.0014.672 ±0.022.164 ±0.09
app-mediumcleanlock-onlycache-onlymodules-onlyno-lockno-cacheno-modulesno-cleanshow-versionrun-scriptcache-only
peer-deps
no-clean
audit
npm@latest26.959 ±1.767.944 ±0.028.856 ±0.031.519 ±0.011.515 ±0.001.413 ±0.015.796 ±0.011.318 ±0.010.139 ±0.000.165 ±0.009.528 ±0.173.052 ±1.55
#752125.791 ±1.427.956 ±0.038.819 ±0.021.509 ±0.011.497 ±0.011.408 ±0.005.839 ±0.031.313 ±0.010.139 ±0.000.166 ±0.009.822 ±0.051.986 ±0.08

Comment threadlib/commands/config.js Outdated
@wraithgar

Copy link
Copy Markdown
Contributor

I think if we're gonna redact we redact. We should acknowledge that there are some values that aren't worth showing at all (and they are currently accounted for) but some that may contain urls with passwords. Proxy and registry come to mind. If we simply pass all of the displayed values through redact (now that we are using it) this would help

@lukekarrys

Copy link
Copy Markdown
ContributorAuthor

+1 for treating registry however we end up treating proxy

@lukekarryslukekarrys changed the title fix(config): protect proxy if it contains basic authfix(config): protect url fields if they contain basic authMay 14, 2024
Comment threadlib/commands/config.js Outdated
@lukekarryslukekarrys changed the title fix(config): protect url fields if they contain basic authfix(config): use redact on config outputMay 14, 2024
Comment threadlib/commands/config.js Outdated
@lukekarrys
lukekarrys merged commit badeac2 into latestMay 14, 2024
@lukekarrys
lukekarrys deleted the lk/protect-proxy branch May 14, 2024 20:49
@github-actionsgithub-actionsBot mentioned this pull request May 14, 2024
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Password in plain text when getting the proxy details from config through CLI

3 participants

@lukekarrys@npm-cli-bot@wraithgar