From 1c06ae370a6155da7bff8b35a84537292485fa59 Mon Sep 17 00:00:00 2001 From: Chris Amow Date: Wed, 26 Aug 2026 01:13:54 -0500 Subject: [PATCH] redact oauth values from debug logs --- docs/install_debug_charts.md | 1 + docs/plan_diagnostics_improvements.md | 2 ++ ops/chart-debug-command | 3 ++- 3 files changed, 5 insertions(+), 1 deletion(-) diff --git a/docs/install_debug_charts.md b/docs/install_debug_charts.md index 638ee37..d3c13df 100644 --- a/docs/install_debug_charts.md +++ b/docs/install_debug_charts.md @@ -45,6 +45,7 @@ on the diagnostics client at: - Preserve the `restrict` and forced-command options in `authorized_keys`. - Verify arbitrary commands and malformed arguments are denied. - Do not print container environment variables or application secrets. +- Redact OAuth `code`, `session`, and `state` query parameters from access logs. - Ensure `status` passes its token to curl through stdin, not an argv `-H` argument visible through `/proc`. - Resolve the container into a variable before Docker calls so selector failure diff --git a/docs/plan_diagnostics_improvements.md b/docs/plan_diagnostics_improvements.md index 2b439f5..0e55b1e 100644 --- a/docs/plan_diagnostics_improvements.md +++ b/docs/plan_diagnostics_improvements.md @@ -111,6 +111,8 @@ Security invariants: `journalctl -t chart-debug`. - Keep secrets off process command lines. The status command supplies `CHART_AUTH_TOKEN` to curl through stdin (`curl --config -`), never `-H`. +- Redact OAuth `code`, `session`, and `state` query parameters as well as token, + secret, password, key and Authorization values in log output. - Assign `resolve_container` before invoking Docker. Calling it inline through command substitution can trap its exit in a subshell and obscure the intended fail-closed return code. diff --git a/ops/chart-debug-command b/ops/chart-debug-command index d6d4fd6..4dbca1c 100755 --- a/ops/chart-debug-command +++ b/ops/chart-debug-command @@ -38,7 +38,8 @@ resolve_container() { redact() { sed -E \ -e 's/(Authorization:[[:space:]]*Bearer[[:space:]]+)[A-Za-z0-9._-]+/\1[REDACTED]/Ig' \ - -e 's/((token|secret|password|api[_-]?key)["=:[:space:]]+)[^,[:space:]"}]+/\1[REDACTED]/Ig' + -e 's/((token|secret|password|api[_-]?key)["=:[:space:]]+)[^,[:space:]"}]+/\1[REDACTED]/Ig' \ + -e 's/([?&](code|session|state)=)[^&[:space:]]+/\1[REDACTED]/Ig' } valid_capture_id() {