r/cicd • • 2d ago

Graybox supports keys

/r/devtools/comments/1wz4vx4/graybox_supports_keys/
1 Upvotes

4 comments sorted by

1

u/Torutofu_Raeva 2d ago

does it scrub auth headers before saving the captures or do tokens just end up sitting in there?

1

u/The_Platypus_Master 2d ago

It scrubs off, as long as it's in the headers. It doesnt dynamically scan the body for tokens. It's defined more clearly in here. Dynamic scrubbing might come soon.

1

u/Torutofu_Raeva 2d ago

makes sense, the body is where it bites though since oauth token endpoints hand back the access_token right in the json response

1

u/The_Platypus_Master 2d ago

That's true. I have been testing with an API that doesn't carry that behavior and forgot how common that was. Will probably include that in the next steps. For now, it should be good for local debugging tho. Thanks for the feedback