From b4eb611c07568934ef87845647718c317a921f57 Mon Sep 17 00:00:00 2001 From: dawg Date: Wed, 14 Jan 2026 23:12:51 +0100 Subject: [PATCH] feat: more aggressively truncate logged access_token (#3264) * partly address #2120 and more aggressively truncate access_token - leaking half of the access token to the logs seems problematic from a security point of view - also noisier than necessary logging - fixed by truncating to at most first 5 chars (e.g. `ya29.`) Signed-off-by: Martin Nowak * feat: more aggressively truncate logged access_token; add unit test and changelog Signed-off-by: Jan Larwig --------- Signed-off-by: Martin Nowak Signed-off-by: Jan Larwig Co-authored-by: Jan Larwig --- CHANGELOG.md | 1 + providers/internal_util.go | 3 ++- providers/internal_util_test.go | 6 ++++++ 3 files changed, 9 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 642be594..70cfaa3e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,7 @@ - [#3197](https://github.com/oauth2-proxy/oauth2-proxy/pull/3197) fix: NewRemoteKeySet is not using DefaultHTTPClient (@rsrdesarrollo / @tuunit) - [#3292](https://github.com/oauth2-proxy/oauth2-proxy/pull/3292) chore(deps): upgrade gomod and bump to golang v1.25.5 (@tuunit) - [#3304](https://github.com/oauth2-proxy/oauth2-proxy/pull/3304) fix: added conditional so default is not always set and env vars are honored fixes 3303 (@pixeldrew) +- [#3264](https://github.com/oauth2-proxy/oauth2-proxy/pull/3264) fix: more aggressively truncate logged access_token (@MartinNowak / @tuunit) # V7.13.0 diff --git a/providers/internal_util.go b/providers/internal_util.go index 52cfd0a7..49e1fd94 100644 --- a/providers/internal_util.go +++ b/providers/internal_util.go @@ -36,7 +36,8 @@ func stripParam(param, endpoint string) string { } if val := values.Get(param); val != "" { - values.Set(param, val[:(len(val)/2)]+"...") + // Truncate by at least half and allow for a maximum of 5 characters + values.Set(param, val[:min(len(val)/2, 5)]+"...") u.RawQuery = values.Encode() return u.String() } diff --git a/providers/internal_util_test.go b/providers/internal_util_test.go index 545e83cb..31952622 100644 --- a/providers/internal_util_test.go +++ b/providers/internal_util_test.go @@ -149,3 +149,9 @@ func TestStripToken(t *testing.T) { expected := "http://local.test/api/test?access_token=dead...&b=1&c=2" assert.Equal(t, expected, stripToken(test)) } + +func TestStripLongToken(t *testing.T) { + test := "http://local.test/api/test?access_token=deadbeefwithsupersecret&b=1&c=2" + expected := "http://local.test/api/test?access_token=deadb...&b=1&c=2" + assert.Equal(t, expected, stripToken(test)) +}