redact oauth values from debug logs

This commit is contained in:
Chris Amow 2026-08-26 01:13:54 -05:00
parent d8dcb84edb
commit 1c06ae370a
3 changed files with 5 additions and 1 deletions

View file

@ -45,6 +45,7 @@ on the diagnostics client at:
- Preserve the `restrict` and forced-command options in `authorized_keys`. - Preserve the `restrict` and forced-command options in `authorized_keys`.
- Verify arbitrary commands and malformed arguments are denied. - Verify arbitrary commands and malformed arguments are denied.
- Do not print container environment variables or application secrets. - Do not print container environment variables or application secrets.
- Redact OAuth `code`, `session`, and `state` query parameters from access logs.
- Ensure `status` passes its token to curl through stdin, not an argv `-H` - Ensure `status` passes its token to curl through stdin, not an argv `-H`
argument visible through `/proc`. argument visible through `/proc`.
- Resolve the container into a variable before Docker calls so selector failure - Resolve the container into a variable before Docker calls so selector failure

View file

@ -111,6 +111,8 @@ Security invariants:
`journalctl -t chart-debug`. `journalctl -t chart-debug`.
- Keep secrets off process command lines. The status command supplies - Keep secrets off process command lines. The status command supplies
`CHART_AUTH_TOKEN` to curl through stdin (`curl --config -`), never `-H`. `CHART_AUTH_TOKEN` to curl through stdin (`curl --config -`), never `-H`.
- Redact OAuth `code`, `session`, and `state` query parameters as well as token,
secret, password, key and Authorization values in log output.
- Assign `resolve_container` before invoking Docker. Calling it inline through - Assign `resolve_container` before invoking Docker. Calling it inline through
command substitution can trap its exit in a subshell and obscure the intended command substitution can trap its exit in a subshell and obscure the intended
fail-closed return code. fail-closed return code.

View file

@ -38,7 +38,8 @@ resolve_container() {
redact() { redact() {
sed -E \ sed -E \
-e 's/(Authorization:[[:space:]]*Bearer[[:space:]]+)[A-Za-z0-9._-]+/\1[REDACTED]/Ig' \ -e 's/(Authorization:[[:space:]]*Bearer[[:space:]]+)[A-Za-z0-9._-]+/\1[REDACTED]/Ig' \
-e 's/((token|secret|password|api[_-]?key)["=:[:space:]]+)[^,[:space:]"}]+/\1[REDACTED]/Ig' -e 's/((token|secret|password|api[_-]?key)["=:[:space:]]+)[^,[:space:]"}]+/\1[REDACTED]/Ig' \
-e 's/([?&](code|session|state)=)[^&[:space:]]+/\1[REDACTED]/Ig'
} }
valid_capture_id() { valid_capture_id() {