diff --git a/backend/app/core/logging_filters.py b/backend/app/core/logging_filters.py index d64f3a642..a45b2b188 100644 --- a/backend/app/core/logging_filters.py +++ b/backend/app/core/logging_filters.py @@ -9,7 +9,9 @@ import them without pulling in ``backend.app.main``'s startup graph. Also holds :data:`URL_CREDENTIALS_PATTERN` and :func:`redact_url_credentials`, the single place where the shape of a -credentialed URL is defined for the whole backend. +credentialed URL is defined for the whole backend, and +:data:`QUERY_TOKEN_PATTERN` / :class:`QueryTokenRedactFilter` for tokens +carried in a query string. """ from __future__ import annotations @@ -60,6 +62,49 @@ def redact_url_credentials(text: str | None) -> str | None: return URL_CREDENTIALS_PATTERN.sub(r"\g\g:[REDACTED]@", text) +# ``?token=`` and its kin. The SPA passes its short-lived WebSocket and +# media tokens in the query string (a browser cannot set headers on a +# WebSocket upgrade, an or a