fix(openrouter): stop logging API key material, use a hash fingerprint

Address Codex review: the debug log previously included the key's
first 10 characters. Replace with a non-reversible SHA-256 fingerprint
so logs remain useful for correlating support reports without ever
exposing key material.
This commit is contained in:
Claude committed 2026-07-14 06:31:18 +00:00
1 parent de7fc7d03c
commit 8155b30c63
1 file changed
+3 -2
+3 -2
View File
@@ -12,6 +12,7 @@ interface GeneratedText {
characterCount: number;
}
import crypto from 'crypto';
import { storage } from '../storage';
export class OpenRouterService {
@@ -35,8 +36,8 @@ export class OpenRouterService {
// Use provided model or fall back to config model
const modelToUse = modelOverride || config.model;
const keyPreview = `${config.apiKey.slice(0, 10)}...(len=${config.apiKey.length})`;
console.log(`[OpenRouter] Generating with model="${modelToUse}" key=${keyPreview} configUserId=${config.userId}`);
const keyFingerprint = crypto.createHash('sha256').update(config.apiKey).digest('hex').slice(0, 8);
console.log(`[OpenRouter] Generating with model="${modelToUse}" keyFingerprint=${keyFingerprint} keyLength=${config.apiKey.length} configUserId=${config.userId}`);
try {
const response = await fetch(this.baseUrl, {