Auditor
Error responses never include stack traces, internal paths or query text.
1.0.4: an error carrying its stack inside BROWSER code is not an HTTP error response. The three response rules (stack in the response, whole exception forwarded, traceback in the response) are applied only to a file that is proven server code OR that writes an HTTP response: a React error boundary that reports `error.stack` to its own report action, and a component that hands `{ name, message, stack }` to a callback of the same page, cross no network boundary and are not analysed (the trace names the file). A worker or browser file that DOES write an HTTP response keeps being judged in full. The debug-mode and development-middleware rules are unchanged. Same runtime criterion as the shared-layer fix: WHERE A FILE RUNS is decided from the FILE (and, when the file alone does not say, from the import graph of the checkout), never from a list of folder names of one particular repository, and a file whose server nature is UNPROVEN is never reported as server code. A monorepo has a SHARED layer — a package the browser bundle and the services both import — and the old rule read every ambiguous file as server: WebCrypto of the browser (`crypto.subtle` in a shared e2ee service that a client component imports) came out as "key generation in server code", once per product sharing the layer. The evidence is now, strongest first: the language (Python, PHP); a `server-only`/`client-only` import or a `'use server'`/`'use client'` directive; a location the framework declares as server (route.ts, middleware, pages/api, app/api, *.server.*, +server, wsgi/asgi); a browser runtime in the code (DOM member, Web Worker scope, `new Worker(`, a React client hook, a browser-environment polyfill such as fake-indexeddb or jsdom); a server runtime in the code (Node built-in, server-only package such as express/mongodb/winston/@aws-sdk, HTTP response sink, Lambda handler export); the IMPORT GRAPH (a module a client-declared file imports runs in the browser, a module that imports a server-proven module runs on a server); the folder convention (`workers/` is no longer one of them: a worker folder is a browser convention as often as a server one); a universal Web API of the browser with no server evidence at all; otherwise unproven, which is never server. Found by the attestation campaign of the platform (2026-09-25): 73 of the 252 high findings of every project were this one classification. (1.0.3: false positive of the attestation of platform/projects/fun (2026-09-24), fixed in the script: un módulo que demuestra correr dentro de un Web Worker (DedicatedWorkerGlobalScope, SharedWorkerGlobalScope, ServiceWorkerGlobalScope, WorkerGlobalScope, importScripts(), self.postMessage o self.onmessage), que responde con postMessage() y que no tiene NINGÚN sumidero de respuesta HTTP es un CANAL DE MENSAJES DEL NAVEGADOR y no se analiza (la traza lo nombra): su receptor es el hilo principal de la misma página, que ya tiene ese código, y el error serializado con su stack es lo que hace depurable un fallo dentro de un worker. Un fichero de worker que SÍ escribe una respuesta HTTP se sigue analizando entero. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
| { id: 'stack-in-response', severity: 'high', re: /(?:res\.(?:json|send)|NextResponse\.json|jsonify|JsonResponse|response\(\)->json)[^\n]{0,200}\b(?:err|error|e|exception)\.stack\b/ }, |
| { id: 'debug-mode-literal', severity: 'high', re: /^\s*DEBUG\s*=\s*True\s*$|app\.run\([^)]*debug\s*=\s*True|['"]debug['"]\s*=>\s*true|APP_DEBUG\s*=\s*true|display_errors\s*=\s*On/im }, // literal only; env(...) never counts |
| { id: 'whole-error-in-response', severity: 'medium', re: /res\.json\(\s*(?:err|error|e)\s*\)|detail\s*=\s*str\(e\)|->getMessage\(\)/ } |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.