Repository navigation
Keep bot keys out of Thruster access logs - #320
Open
thomasklemm wants to merge 4 commits into
Open
thomasklemm wants to merge 4 commits into
thomasklemm wants to merge 4 commits into
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Webhook payloads still distribute credential-bearing paths, and Bearer scheme parsing is incorrectly case-sensitive.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds header-based bot authentication to prevent credentials appearing in Thruster access logs while preserving legacy URLs.
Changes:
- Adds credential-free bot API routes with header/Bearer authentication.
- Preserves pagination paths and updates generated curl commands.
- Adds tests and operator security guidance.
[!TIP]
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or rungh pr ready --undo.
Click "Ready for review" or rungh pr readyto reengage.
| File | Description |
|---|---|
app/controllers/concerns/authentication.rb |
Reads bot credentials from headers. |
app/controllers/messages/by_bots_controller.rb |
Preserves the current route in pagination links. |
app/views/accounts/bots/_bot.html.erb |
Generates header-authenticated curl commands. |
config/routes.rb |
Adds credential-free bot API routes. |
docs/self-hosting.md |
Documents safe bot authentication and logging risks. |
SECURITY.md |
Documents bot-key handling guidance. |
test/controllers/messages/by_bots_controller_test.rb |
Tests header authentication and pagination. |
test/controllers/messages/boosts/by_bots_controller_test.rb |
Tests header-authenticated boosts. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
thomasklemm
added a commit
to roundhouse-rb/once-campfire
that referenced
this pull request
Oct 5, 2026
From thomasklemm:cursor/bot-key-header-not-path-8545 (upstream PR state at merge: OPEN).
thomasklemm
added a commit
to roundhouse-rb/once-campfire
that referenced
this pull request
Oct 5, 2026
From thomasklemm:cursor/bot-key-header-not-path-8545 (upstream PR state at merge: OPEN).
thomasklemm
added a commit
to roundhouse-rb/once-campfire
that referenced
this pull request
Oct 5, 2026
…aths preview already merged basecamp#306. Stacking basecamp#320 must not drop the response.code == "200" check on attachment replies.
Accept X-Campfire-Bot-Key or Authorization: Bearer on /rooms/:id/bot/... so the credential is not in the path Thruster logs. The old path still works; curl snippets on the bots page use the header form. Fixes basecamp#272. Co-authored-by: Thomas Klemm <github@tklemm.eu>
Share the nested messages/boosts tree between the header path and the legacy bot-key path. Build pagination Link headers from the current request so they follow whichever form the client used. Co-authored-by: Thomas Klemm <github@tklemm.eu>
Keep room.path as the legacy URL. Add api_path plus bot_key so new clients can POST with a header. HTTP auth schemes are case-insensitive. Co-authored-by: Thomas Klemm <github@tklemm.eu>
Thruster logs query as well as path, so accepting ?bot_key= on /rooms/:id/bot/... would reopen the credential leak. Read the key only from the path segment, X-Campfire-Bot-Key, or Authorization. Trim docs to self-hosting and cover the rejection in tests. Co-authored-by: Thomas Klemm <github@tklemm.eu>
Contributor
Author
|
Rebased onto current
|
cursor
Bot
force-pushed
the
cursor/bot-key-header-not-path-8545
branch
from
October 7, 2026 19:54
d2cfd56 to
903cb23
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Thruster's access log records the raw path (and query), so bot keys in
/rooms/:id/:bot_key/messagessurvive Rails' log scrubber.Approach
/rooms/:id/bot/messageswithX-Campfire-Bot-KeyorAuthorization: BearerLinkheaders follow the current requestroom.pathand addroom.api_path+room.bot_keyfor header authbot_keyis ignored (Thruster logsquerytoo)Fixes #272.