Skip to content

Explore PII-safe Request Logging #80

Description

@adeutscher

This issue is a reminder to explore an LLM-proposed item that I feel has merit.

LLM Suggestion Content

ILogger is everywhere, but there is no demonstrated rule for what must not be logged. Middleware or a destructor that redacts Authorization, emails, and upload checksums, plus a scoped request id, would show a production logging policy. Pair it with a test that fails if a known secret appears in log output.

LLM Suggestion Commentary

  • Maybe it's just the late hour I'm filing this ToDo item at, but I'm not 100% understanding why upload checksums need to be updated.
    • It's not completely lost on me, though. It's not as much of a smoking gun as an e-mail, but I could see a log message of " uploaded ", therefore someone with ill intent could look for that file with that checksum. Or something. It's a bit of a stretch, and maybe I'm just tired.
  • I'll need to clarify the scope of redaction. Would keeping broad details of an email or a partial checksum still be acceptable?

Documentation Action Item

Before closing, document how we apply our redaction in a docs/patterns/ document.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions