Remove plaintext bearer token from warning logs #7
Labels
No Label
ai-changes-requested
ai-failed
ai-merged
ai-pr-opened
ai-reviewed
ai-reviewing
ai-reviewing
ai-working
bug
enhancement
evolution
performance
phase-0
phase-1a
phase-1b
phase-1c
phase-1d
security
tech-debt
todo
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: cal/paper-dynasty-database#7
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Pattern `logging.warning(f'Bad Token: {token}')` used in `teams.py`, `gamerewards.py`, `events.py`, and many other routers when auth fails. Full bearer token written to log file. Affects at least 15 router files.
Priority: high
Fixed in PR #55: #55
Replaced all
logging.warning(f'Bad Token: {token}')calls withlogging.warning('Bad Token: [REDACTED]')across 30 router files. The f-string was dropped since no interpolation is needed after redacting the token.