Redmine/requests exceptions may embed the request URL containing the API key (?key=SECRET) or the X-Redmine-API-Key header value. The CLI printed the raw exception text to stderr, leaking the key into terminals and logs. Add _sanitize_error_text() which masks 'key=<value>' query params and the X-Redmine-API-Key header as 'key=***' / 'X-Redmine-API-Key: ***', and apply it to every exception-derived message printed to stderr (fetch errors in main() and SMTP errors in _save_and_maybe_send()). Full traceback with original exception details is now available under both --verbose and --debug (previously only --debug, only for RedmineAPIError). Exit codes and error-handling structure unchanged. Closes #55
58 KiB
58 KiB