feat: more aggressively truncate logged access_token (#3264)

* partly address #2120 and more aggressively truncate access_token

- leaking half of the access token to the logs seems problematic from
  a security point of view
- also noisier than necessary logging
- fixed by truncating to at most first 5 chars (e.g. `ya29.`)

Signed-off-by: Martin Nowak <code@dawg.eu>

* feat: more aggressively truncate logged access_token; add unit test and changelog

Signed-off-by: Jan Larwig <jan@larwig.com>

---------

Signed-off-by: Martin Nowak <code@dawg.eu>
Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
This commit is contained in:
dawg
2026-01-14 23:12:51 +01:00
committed by GitHub
co-authored by Jan Larwig
parent f3dcffed27
commit b4eb611c07
3 changed files with 9 additions and 1 deletions
+2 -1
View File
@@ -36,7 +36,8 @@ func stripParam(param, endpoint string) string {
}
if val := values.Get(param); val != "" {
values.Set(param, val[:(len(val)/2)]+"...")
// Truncate by at least half and allow for a maximum of 5 characters
values.Set(param, val[:min(len(val)/2, 5)]+"...")
u.RawQuery = values.Encode()
return u.String()
}
+6
View File
@@ -149,3 +149,9 @@ func TestStripToken(t *testing.T) {
expected := "http://local.test/api/test?access_token=dead...&b=1&c=2"
assert.Equal(t, expected, stripToken(test))
}
func TestStripLongToken(t *testing.T) {
test := "http://local.test/api/test?access_token=deadbeefwithsupersecret&b=1&c=2"
expected := "http://local.test/api/test?access_token=deadb...&b=1&c=2"
assert.Equal(t, expected, stripToken(test))
}