mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
With LDAP auth in use, the debug log carried the full user DN on successful auth -- e.g. "(DN: CN=Joe Schmoe,CN=Users,DC=ad,DC=example,DC=com, ...)". A DN's leaf CN is the user's real name, PII on par with the email address already redacted, and it passed straight into an uploaded support bundle. The log sanitizer (shared by the support bundle and the in-app bug report) had no DN pattern; DNs also leak via ldap3 exception strings and group-mapping logs. - sanitize_log_content: redact LDAP DNs to [DN] -- a run of >=2 attr=value RDN components (CN/OU/DC/UID/...). The value class excludes <>;+ (RFC 4514 requires them escaped in a value) so the final comma-unbounded component doesn't swallow trailing log text such as "-> GroupName". Ordinary key=value lines are untouched. - ldap_service: stop logging the raw DN on successful auth (username + group count suffices), keeping the PII off disk even before bundle sanitization.