fix(ws): redact access_key and ticket from WebSocket lifecycle logs - #155
Open
Xuxchloris wants to merge 1 commit into
Open
fix(ws): redact access_key and ticket from WebSocket lifecycle logs#155Xuxchloris wants to merge 1 commit into
Xuxchloris wants to merge 1 commit into
Conversation
Client._connect()/_disconnect() logged the full WS endpoint URL at INFO level; the URL query carries access_key and ticket credentials, leaking them to stdout/journals/log collectors. Adds _redact_conn_url() which masks those two query values for logging while preserving the rest of the URL, and uses it at both log sites. The URL passed to websockets.connect() is unchanged. Fixes larksuite#141.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #141.
Problem
Client._connect()and_disconnect()log the complete WebSocket connection URL at INFO level. The URL returned by the Lark WebSocket endpoint contains sensitiveaccess_keyandticketquery values, so lifecycle logs can disclose credentials to stdout, journals, or downstream log collectors.Change
_redact_conn_url(url)helper inlark_oapi/ws/client.py: parses the URL and masks theaccess_keyandticketquery values (***) while preserving the rest of the URL. Returns the input untouched when there is no query.connected to …,disconnected to …) now log the redacted URL. The URL passed towebsockets.connect()is unchanged.Tests
lark_oapi/ws/tests/test_redact_conn_url.py:None/empty input is handled.Verification
python -m pytest lark_oapi/ws/tests/test_redact_conn_url.py— 3/3 pass.