Commit 77a42a8b4f

77a42a8b4f3dd89e631f8246bdea3e95f83bac6a

parent: 6e9dea95d0

Unsigned

cmc <hello@cleberg.net> · 2026-07-20 16:56 UTC

fix: harden webhook transport and gate debug logging

Require HTTPS for outbound integration webhooks. Webhook URLs are
themselves secrets (Slack in particular), so an http:// endpoint leaked
both the URL and the alert payload in cleartext.

Disable DomainDebugLog in release builds. Every message used
privacy: .public, which opted out of OSLog redaction and wrote looked-up
domains to the unified log in shipped builds.

Layout: unified · split

DomainDig/DomainDig/DomainDebugLog.swift +4
@@ -2,7 +2,11 @@ import Foundation
2import os 2import os
3 3
4enum DomainDebugLog { 4enum DomainDebugLog {
5#if DEBUG
5 static let enabled = true 6 static let enabled = true
7#else
8 static let enabled = false
9#endif
6 private static let logger = Logger(subsystem: "co.zerolabs.domain-dig", category: "Debug") 10 private static let logger = Logger(subsystem: "co.zerolabs.domain-dig", category: "Debug")
7 11
8 static func debug(_ message: String) { 12 static func debug(_ message: String) {
DomainDig/IntegrationService.swift +1 −1
@@ -555,7 +555,7 @@ private enum HTTPIntegrationClient {
555 headers: [String: String], 555 headers: [String: String],
556 timeoutSeconds: Double 556 timeoutSeconds: Double
557 ) async throws { 557 ) async throws {
558 guard let url = URL(string: urlString) else { 558 guard let url = URL(string: urlString), url.scheme?.lowercased() == "https" else {
559 throw IntegrationError.invalidURL 559 throw IntegrationError.invalidURL
560 } 560 }
561 561