The header rule stopped at the first whitespace or quote, so a multi-part credential such as a Digest or AWS SigV4 authorization value lost only its first token. It also matched any bare word carrying a credential hint, so prose and paths like `auth: failed` or `/v1/tokens:list` were redacted. The value is now bounded by its context: to the closing quote inside a quoted shell argument, and to the end of a comma-separated `key=value` list or a single token when unquoted. A header name must be hyphenated or underscored, or be the bare `authorization` or `apikey`; the `www-authenticate` and `proxy-authenticate` challenge headers are excluded. The recognized scheme list follows the IANA registry plus `AWS4-HMAC-SHA256` and `Token`. Claude-Session: https://claude.ai/code/session_01RYigf3eMFJjey9iKRApPGE |
||
|---|---|---|
| .. | ||
| adapter-utils | ||
| adapters | ||
| db | ||
| google-sheets-mcp-server | ||
| kv-demo-mcp-server | ||
| mcp-server | ||
| paperclip-eval-kernel | ||
| paperclip-runner | ||
| plugins | ||
| shared | ||
| skills-catalog | ||
| tailscale-https-broker | ||
| teams-catalog | ||