Files
treg/tests/test_log_redaction.py
UncleCode 298fb18d7b fix(logging): stop writing provider URLs (and query-string keys) to the log
`MCPServer(...)` calls `logging.basicConfig(level="INFO")` by default, so the root logger ran at
INFO and httpx/httpx2 logged "HTTP Request: GET <full url>" for every provider call. Providers that
take their key in the query string (SerpAPI, ZeroBounce, Datagma, Twelve Data, ...) had the key in
the production log, next to the caller's search values.

The four HTTP client loggers (httpx, httpx2, httpcore, httpcore2) now log at WARNING. treg's own
lines keep INFO.

Tests: tests/test_log_redaction.py (fails without the fix).
2026-09-30 14:41:48 +08:00

25 lines
1015 B
Python

"""Provider addresses never reach the log: the HTTP clients log each request's full URL at INFO,
and a query-string key (SerpAPI `api_key`, Datagma `apiId`, ...) is part of that URL."""
from __future__ import annotations
import logging
import treg.api # noqa: F401 - builds the MCP servers, which turn the root logger on at INFO
def test_the_http_clients_log_nothing_below_warning():
assert logging.getLogger().getEffectiveLevel() <= logging.INFO # the reason this test exists
for name in ("httpx", "httpx2", "httpcore", "httpcore2"):
assert logging.getLogger(name).getEffectiveLevel() >= logging.WARNING, name
async def test_a_provider_call_writes_no_url_to_the_log(caplog):
import httpx
caplog.set_level(logging.INFO)
transport = httpx.MockTransport(lambda request: httpx.Response(200))
async with httpx.AsyncClient(transport=transport) as client:
await client.get("https://serpapi.com/search?q=x&api_key=SECRET123")
assert "SECRET123" not in caplog.text