Description
The Cmd+5 API tracker keeps complete request and response payload objects in memory. Tauri invokes currently store both tauriArgs: args and data: args, then attach the complete response. HTTP tracking similarly keeps request bodies, headers, params, responses, and error bodies.
The tracker has a count cap (MAX_API_CALLS = 300) but no byte budget, payload truncation, or sensitive-field redaction. A small number of large payloads can therefore retain substantial WebView memory even though the record count is bounded.
This is separate from #425. That issue removes full-buffer shell retransmission at the source; this issue ensures the diagnostic tool cannot retain arbitrarily large payloads from shell, snapshots, file content, or other commands.
Current Behavior
Relevant paths:
src/util/monitoring/apiTrackerState.ts
- retains the latest 300
ApiCall objects by count only
src/util/monitoring/apiTrackerTauri.ts
- stores
tauriArgs: args
- stores
data: args
- stores the complete
response
src/util/monitoring/apiTrackerHttp.ts
- stores request data/headers/params and complete response/error bodies
src/modules/shared/DevTools/APICallPanel/components/ApiCallDetails.tsx
- truncates formatted display, but the original payload remains retained in memory
Closing the panel stops instrumentation and clears in-flight timing state, but existing API records remain until the next clear/open or count eviction. Stopping collection is not the same as releasing already retained payloads.
Steps to Reproduce
- Open Cmd+5 to enable API tracking.
- Trigger Tauri or HTTP calls with large request/response payloads, such as shell output, snapshots, file content, or large JSON responses.
- Observe that the tracker stores the original payload objects, even though the details UI displays only a short preview.
- Close the panel and inspect retained WebView heap references.
Expected Behavior
The API tracker should provide useful diagnostics without retaining unbounded payload bytes or exposing secrets.
Proposed Fix
- Introduce a tracker-wide byte budget in addition to record-count limits.
- Summarize or truncate payloads at ingestion time, before storing them.
- Store metadata for oversized payloads:
- approximate byte length;
- type/shape;
- bounded preview;
- truncation/redaction flags;
- optional hash.
- Redact sensitive keys recursively, including authorization, token, password, secret, cookie, and API-key variants.
- Avoid duplicate retention of the same Tauri args in both
tauriArgs and data.
- Define a clear close-panel memory policy: release stored payload bodies immediately, or clear all records.
- Apply the same policy to Tauri, fetch/axios, errors, timer metadata, and push metadata.
Acceptance Criteria
Verification
- Unit test a multi-megabyte Tauri arg and response; retained tracker bytes remain within budget.
- Unit test nested secret redaction for Tauri and HTTP payloads.
- Unit test eviction/truncation when a single record exceeds the total budget.
- Unit test that closing/clearing releases stored bodies.
- Heap/profile test with repeated large calls while Cmd+5 is open and after it closes.
Environment / Known Affected Version
- Current
develop at issue discovery: e24957ca7
- Incident version:
2e24b726dad67c0ac98a096d45addb8631814259
- Observed platform: macOS
Related
Description
The Cmd+5 API tracker keeps complete request and response payload objects in memory. Tauri invokes currently store both
tauriArgs: argsanddata: args, then attach the complete response. HTTP tracking similarly keeps request bodies, headers, params, responses, and error bodies.The tracker has a count cap (
MAX_API_CALLS = 300) but no byte budget, payload truncation, or sensitive-field redaction. A small number of large payloads can therefore retain substantial WebView memory even though the record count is bounded.This is separate from #425. That issue removes full-buffer shell retransmission at the source; this issue ensures the diagnostic tool cannot retain arbitrarily large payloads from shell, snapshots, file content, or other commands.
Current Behavior
Relevant paths:
src/util/monitoring/apiTrackerState.tsApiCallobjects by count onlysrc/util/monitoring/apiTrackerTauri.tstauriArgs: argsdata: argsresponsesrc/util/monitoring/apiTrackerHttp.tssrc/modules/shared/DevTools/APICallPanel/components/ApiCallDetails.tsxClosing the panel stops instrumentation and clears in-flight timing state, but existing API records remain until the next clear/open or count eviction. Stopping collection is not the same as releasing already retained payloads.
Steps to Reproduce
Expected Behavior
The API tracker should provide useful diagnostics without retaining unbounded payload bytes or exposing secrets.
Proposed Fix
tauriArgsanddata.Acceptance Criteria
Verification
Environment / Known Affected Version
developat issue discovery:e24957ca72e24b726dad67c0ac98a096d45addb8631814259Related