clockworklabs / clockworklabs/SpacetimeDB
Stop logging PG tokens and classify authentication failures
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 25.2k
- Forks
- 1.1k
- Avg merge
- 2d 7h
- Merged PRs (30d)
- 46
Description
Follow-up from https://github.com/clockworklabs/SpacetimeDB/pull/5640.
crates/pg/src/pg_server.rs, remove the supplied token used as identity from authentication logs and distinguish invalid credentials from identity-provider failures so they can use appropriate log levels.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in crates/pg/src/pg_server.rs and review the authentication logging added or affected by pull request 5640. The work is complete when supplied identity tokens no longer appear in authentication logs and invalid credentials are distinguished from identity-provider failures with appropriate log levels.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- postgres, rust
- Domain
- authentication, databases, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 70/100