Skip to content

Environment variables passed to logs should be sanitised out of the logs #1436

Closed
@krassowski

Description

@krassowski

Description

In the --debug mode the server logs environment variables which may be sensitive. These should not be included IMO:

self.log.debug("Kernel args: %r", kwargs)

Maybe something like self.log.debug("Kernel args: %r", {k: v for k, v in kwargs.items() if k != 'env'}) ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions