Skip to content

Stop reporting the values of invalid env vars / sysprops / config #3104

Description

@jeffalder

Is your feature request related to a problem? Please describe.

A deployment specified NEW_RELIC_API_KEY in the environment of the container. The Java agent read this and sent it to the collector as an api_key value that shows, unredacted, under the Agent initialization UI.

Feature Description

While we are removing NEW_RELIC_API_KEY from that deployment, and while we are pursuing a separate fix to make the Agent initialization UI a little more redactive, I think the agent should also modify its behavior and, if it detects an invalid configuration, it should say so. That way the user knows that a value was specified but also that it wasn't parsed. As we don't know if random values are actually sensitive, we should avoid sending any of the values (after all, they could represent a log4shell-like attack either on the consumer or on a browser).

For example, if NEW_RELIC_NOT_A_VAR is set in the environment, it should send:

not_a_var: Invalid env var NEW_RELIC_NOT_A_VAR

If -Dnewrelic.not_a_var is provided on the command-line, it should send:

not_a_var: Invalid system property newrelic.not_a_var

Describe Alternatives

You could also simply not send invalid values at all, but log them instead. That way, they never leave the execution environment.

Priority

Really Want

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

feature requestSuggestion for a new product enhancement or change

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions