Files
apartment-dashboard-api/__tests__
Stephen Minakian 41e252410e
All checks were successful
CI/CD Pipeline - Apartment API / Send Webhook Notification (pull_request) Successful in 2s
CI/CD Pipeline - Apartment API / Build & Push Image (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Deploy to Production (pull_request) Has been skipped
CI/CD Pipeline - Apartment API / Scan Dependencies (pull_request) Successful in 13s
CI/CD Pipeline - Apartment API / Lint & Test (pull_request) Successful in 44s
feat: sanitize error messages before recording to scraper_runs
Add sanitizeError() and sanitizeMessage() functions that strip sensitive
information from error messages before they are stored in scraper_runs
history. This prevents accidental exposure of infrastructure details in
the database.

Sanitization covers:
- Unix and Windows file paths (e.g., /home/deploy/app/..., C:\Users\...)
- MongoDB connection strings (mongodb:// and mongodb+srv://)
- Credential patterns (API_KEY=, password=, secret=, token=)
- Stack trace file path references

The error type/name (e.g., MongoServerError, TypeError) and general
debugging description are preserved to maintain diagnostic usefulness.

Applied in runScrape() catch block before calling recordScraperRun(),
ensuring only sanitized messages reach the database.

Added 18 new tests covering all sanitization categories: file paths,
connection strings, credentials, error type preservation, description
preservation, stack trace removal, and integration with recordScraperRun.
2026-02-06 23:41:47 -07:00
..