Skip to content

Potential fix for code scanning alert no. 1: Cleartext logging of sensitive information - #1

Draft
boredpolymath wants to merge 1 commit into
mainfrom
alert-autofix-1
Draft

boredpolymath wants to merge 1 commit into
mainfrom
alert-autofix-1

Conversation

@boredpolymath

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/boredpolymath/adcleanse/security/code-scanning/1

The safest fix is to stop logging the sensitive identifier (uid) and keep a generic success message.
In src-tauri/src/auth/webview.rs, update the log::info! call inside intercept_credentials (the Some(uid), Some(xs), Some(datr) match arm) to remove {} and uid from the message arguments.

This preserves existing functionality (credential extraction, state update, and return value) while eliminating cleartext logging of sensitive/user-derived data. No new methods, types, or imports are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…sitive information

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant