Skip to content

fix(devtools): bound and redact tracked API payloads #426

Description

@ShiboSheng

Description

The Cmd+5 API tracker keeps complete request and response payload objects in memory. Tauri invokes currently store both tauriArgs: args and data: args, then attach the complete response. HTTP tracking similarly keeps request bodies, headers, params, responses, and error bodies.

The tracker has a count cap (MAX_API_CALLS = 300) but no byte budget, payload truncation, or sensitive-field redaction. A small number of large payloads can therefore retain substantial WebView memory even though the record count is bounded.

This is separate from #425. That issue removes full-buffer shell retransmission at the source; this issue ensures the diagnostic tool cannot retain arbitrarily large payloads from shell, snapshots, file content, or other commands.

Current Behavior

Relevant paths:

  • src/util/monitoring/apiTrackerState.ts
    • retains the latest 300 ApiCall objects by count only
  • src/util/monitoring/apiTrackerTauri.ts
    • stores tauriArgs: args
    • stores data: args
    • stores the complete response
  • src/util/monitoring/apiTrackerHttp.ts
    • stores request data/headers/params and complete response/error bodies
  • src/modules/shared/DevTools/APICallPanel/components/ApiCallDetails.tsx
    • truncates formatted display, but the original payload remains retained in memory

Closing the panel stops instrumentation and clears in-flight timing state, but existing API records remain until the next clear/open or count eviction. Stopping collection is not the same as releasing already retained payloads.

Steps to Reproduce

  1. Open Cmd+5 to enable API tracking.
  2. Trigger Tauri or HTTP calls with large request/response payloads, such as shell output, snapshots, file content, or large JSON responses.
  3. Observe that the tracker stores the original payload objects, even though the details UI displays only a short preview.
  4. Close the panel and inspect retained WebView heap references.

Expected Behavior

The API tracker should provide useful diagnostics without retaining unbounded payload bytes or exposing secrets.

Proposed Fix

  1. Introduce a tracker-wide byte budget in addition to record-count limits.
  2. Summarize or truncate payloads at ingestion time, before storing them.
  3. Store metadata for oversized payloads:
    • approximate byte length;
    • type/shape;
    • bounded preview;
    • truncation/redaction flags;
    • optional hash.
  4. Redact sensitive keys recursively, including authorization, token, password, secret, cookie, and API-key variants.
  5. Avoid duplicate retention of the same Tauri args in both tauriArgs and data.
  6. Define a clear close-panel memory policy: release stored payload bodies immediately, or clear all records.
  7. Apply the same policy to Tauri, fetch/axios, errors, timer metadata, and push metadata.

Acceptance Criteria

  • Tracker storage is bounded by total estimated bytes, not only record count.
  • Large request/response bodies are truncated or summarized before entering tracker state.
  • Sensitive fields are redacted recursively and never retained in plaintext tracker records.
  • Tauri args are not retained twice under separate fields.
  • Shell/exec, snapshot, and file-content payloads follow the same bounded policy.
  • Closing or clearing the panel releases retained large payload bodies according to a documented policy.
  • The details panel clearly shows when content was truncated or redacted.
  • Hotspot aggregation still works from metadata after body truncation.

Verification

  • Unit test a multi-megabyte Tauri arg and response; retained tracker bytes remain within budget.
  • Unit test nested secret redaction for Tauri and HTTP payloads.
  • Unit test eviction/truncation when a single record exceeds the total budget.
  • Unit test that closing/clearing releases stored bodies.
  • Heap/profile test with repeated large calls while Cmd+5 is open and after it closes.

Environment / Known Affected Version

  • Current develop at issue discovery: e24957ca7
  • Incident version: 2e24b726dad67c0ac98a096d45addb8631814259
  • Observed platform: macOS

Related

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions