Skip to content

Do not log the login password and json web token - #103

Closed
Puttichai wants to merge 1 commit into
masterfrom
scrub_credentials_from_logs_20260910
Closed

Puttichai wants to merge 1 commit into
masterfrom
scrub_credentials_from_logs_20260910

Conversation

@Puttichai

Copy link
Copy Markdown
Contributor

Generated by AI, do not review or read yet.

Description

GraphClientBase logs its query variables and its response at verbose level. For the Login
mutation the variables carry the plaintext password and the response carries the returned json
web token, so both were written to the log:

  • _CallGraphAPI: variables, and the response
  • _CallSubscribeGraphAPI: variables

All three now go through a small local scrubber that replaces the value of any key whose
lowercase name contains password, secret, token, credential or apikey with ***,
recursing into dicts and lists.

The scrubber is local to this file rather than imported, because this package has to work with
none of its optional dependencies installed. A shared helper that silently did not scrub when
absent would be worse than none. It never raises, so it is safe to call from a logging
statement, and all three call sites already sit inside log.isEnabledFor checks so the copy is
only made when the message is actually emitted.

Example

Before:

executing graph query with variables {'username': 'user', 'password': 'hunter2'}
got response from graph query: {'Login': {'userId': 'u1', 'jsonWebToken': 'eyJhbGciOi...'}}

After:

executing graph query with variables {'username': 'user', 'password': '***'}
got response from graph query: {'Login': {'userId': 'u1', 'jsonWebToken': '***'}}

… web token

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Puttichai Puttichai added the AI-generated Opened by an AI assistant label Sep 10, 2026
@Puttichai Puttichai self-assigned this Sep 10, 2026
@Puttichai

Copy link
Copy Markdown
Contributor Author

Closing this. See also https://tiny.mujin.co.jp/axlfl

@Puttichai Puttichai closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI-generated Opened by an AI assistant

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant