Skip to content

[GrantFox][High] Redact wallet and tenant data from telemetry #988

Description

@greatest0fallt1me

Summary

Redact wallet and tenant data from telemetry

Why this matters

Client telemetry must not capture secrets, full payloads, or unnecessary identifiers.

Scope

Define an allowlisted event schema and apply redaction to errors, network events, and promise rejections.

Acceptance criteria

  • Only allowlisted fields are emitted.
  • Addresses and tenant IDs follow the redaction policy.
  • Tokens, signatures, request bodies, and seed material never appear.
  • Forbidden-value fixtures prove no leakage.

Validation

Add regression coverage for existing behavior, failure modes, authorization boundaries, and compatibility. The implementation must pass the repository CI checks.

Non-goals

  • Typo-only, formatting-only, or documentation-only changes.
  • Unrelated refactors or dependency upgrades.
  • Weakening existing security, authorization, CI, or production safeguards.

Contributor application

Before implementation, comment with relevant experience, a 1–4 bullet approach, and an estimate for opening the first draft PR. Wait for maintainer assignment before coding.

PR requirements

Use a feature branch, include Closes #<issue-number>, check every acceptance criterion, link criteria to code/tests, explain security and failure-mode considerations, and pass CI.

Reward-readiness

This is a substantive GrantFox campaign issue. Merge and CI success do not by themselves guarantee reward eligibility; final reward-readiness is determined by campaign review.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions