Skip to main content
Introducing packages.sweber.dev
All posts
Release1 min read

Logarithm 0.5.1: redaction now covers snake_case names

A security fix: sensitive fields such as access_token, api_key and Authorization are now redacted in every spelling, not only camelCase. Update recommended.

By Seya Weber

Logarithm 0.5.1 is out on npm and fixes a redaction gap. We recommend that everyone updates.

What was wrong

Logarithm never stores the values of sensitive fields such as passwords and tokens. It replaces them with [redacted] in changes and metadata, also inside nested objects. The default list of names was matched in a case-insensitive way, but only for the camelCase spellings. A payload from a Rails or Python backend, a webhook or an OAuth library that uses access_token, api_key or client_secret was therefore stored in the clear.

What changed

Names now match regardless of case and of the separators _ and -. apiKey, api_key, API-KEY and Api_Key are all the same name, and names you pass as redact are matched the same way. The default list is also longer: authorization, clientSecret, secretKey, passphrase, sessionToken, cookie, currentPassword, newPassword, oldPassword and passwordConfirmation are redacted now.

await audit.record({
  action: "integration.connected",
  actor: { id: "u_anna" },
  after: { provider: "stripe", access_token: "sk_live_…", headers: { Authorization: "Bearer …" } },
})
// stored: access_token "[redacted]", headers.Authorization "[redacted]"

What you should check

Events that were recorded with an earlier version keep what was stored then. If you recorded payloads with snake_case secrets before, search your audit table for those field names and rotate the affected secrets. Logarithm Pro's retention can delete old events if you prefer to drop them.

The release is built and published by GitHub Actions with npm provenance, so the package on npm links to the commit and workflow behind it. The repository now has a SECURITY.md with the reporting channel.

pnpm add @sweberdev/logarithm@latest
Package in this post

Logarithm

A self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

pnpm add @sweberdev/logarithm @sweberdev/logarithm-react
View package

Related posts

Release

Logarithm Pro 0.8.0 released

Anomaly detection that learns what is normal for each tenant, so quiet customers get sensitive alerts and busy customers get fewer false alarms.

Logarithm
Release

Logarithm 0.3.0 released

Counts and breakdowns for dashboards, typed action catalogs, a MySQL and MariaDB store, and in Logarithm Pro alerts to Slack and Teams plus anomaly detection for unusual exports, deletions and failed logins.

Logarithm
Release

Logarithm 0.4.0 released

French and Italian for the activity log, and in Logarithm Pro an S3 and Cloudflare R2 archive for expired events plus log entries that prove your retention policy and erasures actually ran.

Logarithm