From 0b35bbd444354cfa0d4b8ddf0af9ace75e494ee7 Mon Sep 17 00:00:00 2001 From: maziggy Date: Wed, 7 Oct 2026 13:33:49 +0200 Subject: [PATCH] Mask query-string tokens in uvicorn's log lines and support bundles --- backend/app/core/logging_filters.py | 47 +++++++- backend/app/main.py | 7 ++ backend/app/services/log_reader.py | 6 +- .../tests/unit/test_query_token_redaction.py | 112 ++++++++++++++++++ 4 files changed, 170 insertions(+), 2 deletions(-) create mode 100644 backend/tests/unit/test_query_token_redaction.py diff --git a/backend/app/core/logging_filters.py b/backend/app/core/logging_filters.py index d64f3a642..a45b2b188 100644 --- a/backend/app/core/logging_filters.py +++ b/backend/app/core/logging_filters.py @@ -9,7 +9,9 @@ import them without pulling in ``backend.app.main``'s startup graph. Also holds :data:`URL_CREDENTIALS_PATTERN` and :func:`redact_url_credentials`, the single place where the shape of a -credentialed URL is defined for the whole backend. +credentialed URL is defined for the whole backend, and +:data:`QUERY_TOKEN_PATTERN` / :class:`QueryTokenRedactFilter` for tokens +carried in a query string. """ from __future__ import annotations @@ -60,6 +62,49 @@ def redact_url_credentials(text: str | None) -> str | None: return URL_CREDENTIALS_PATTERN.sub(r"\g\g:[REDACTED]@", text) +# ``?token=`` and its kin. The SPA passes its short-lived WebSocket and +# media tokens in the query string (a browser cannot set headers on a +# WebSocket upgrade, an or a