aio logger debug logging is logging client_secret and tokens
Open
bug
- Dominant language
- JavaScript
- Stars
- 6
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Description
Should this be logged? If it should be logged, perhaps we should obfuscate (print out the last N chars only, just for debugging purposes)
Contributor guide
Research direction
Start by tracing the aio logger's debug output in aio-lib-ims and identify where client_secret and tokens are included. Determine whether sensitive authentication values can appear in logs, then verify that the completed change no longer exposes them while preserving useful debugging information.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100