Repository navigation
[debugger] Test PII redaction in log probe messages - #7471
Conversation
|
|
🎉 All green!🧪 All tests passed 🔗 Commit SHA: 144e82e | Docs | View more details | Give us feedback! |
62e8050 to
d1fe4f2
Compare
There was a problem hiding this comment.
More details
The updated PII workloads and line-probe mappings resolve consistently across the enabled Java, .NET, Python, Ruby, and Node.js fixtures, and the new rendered-message checks cover the introduced secret shapes without exposing a diff-only regression.
🤖 Datadog Autotest · Commit d1fe4f2 · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d1fe4f2fb2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Bits Code status: ✅ Done Comment @DataDog to request changes |
d1cae17 to
cbe8dd1
Compare
Add rendered-message coverage for sensitive identifiers, object members, literal and computed map keys, configured types, excluded identifiers, and a non-sensitive control.
Co-authored-by: Cursor <cursoragent@cursor.com>
cbe8dd1 to
144e82e
Compare
There was a problem hiding this comment.
More details
The PII message tests use language-specific probe lines, check exact redaction, block raw secret values, and disable unsupported cases through manifests. No concrete defect appears in these changes.
🤖 Datadog Autotest · Commit 144e82e · What is Autotest? · @DataDog review to ask questions · Any feedback? Reach out in #autotest
Motivation
Dynamic Instrumentation / Live Debugger already redacts PII in snapshots, but rendered log-probe messages use separate evaluation and serialization paths that can expose secrets or emit non-canonical placeholders. We need end-to-end coverage that verifies every sensitive expression emits the exact lowercase
{redacted}placeholder and never includes the raw value.Changes
CustomPiifixtures across Java, Java OTel, Python, .NET, and Node.js weblogs.Validation
./format.shWorkflow
🚀 Once your PR is reviewed and the CI green, you can merge it!
🛟 #apm-shared-testing 🛟
Reviewer checklist
tests/ormanifests/is modified ? I have the approval from R&P teambuild-XXX-imagelabel is present