Skip to content

fix(ui): keep auth tokens out of WebSocket connection logs - #622

Open
blueberrycongee wants to merge 1 commit into
OpenBMB:mainfrom
blueberrycongee:fix/redact-websocket-token-log
Open

blueberrycongee wants to merge 1 commit into
OpenBMB:mainfrom
blueberrycongee:fix/redact-websocket-token-log

Conversation

@blueberrycongee

Copy link
Copy Markdown
Contributor

The WebSocket upgrade handler and the connection handler both log the full request URL. When local login is enabled (PILOTDECK_DISABLE_LOCAL_AUTH=0), the frontend passes the JWT as ?token= on /ws and /shell, so every connection and reconnect writes a reusable auth token to server output (and, for desktop runtimes with login enabled, to runtime.log). The rejected-token path logs it too, since logging happens before verification.

The query string adds nothing when debugging connections, since the path already shows which endpoint was hit, so this change logs only the path. Authentication behavior is unchanged, and the default no-login mode is unaffected because no token is sent there.

Co-authored-by: WUU Agent <305930189+wuu-agent[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant