Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK
What to build
Harden Otlp:Endpoint validation and startup logging. The app currently accepts plaintext HTTP endpoints and logs resolved endpoint URIs. A URI containing userinfo, query credentials, or sensitive tenant/vendor parameters could leak into console logs, while plaintext export exposes telemetry and authentication headers in transit.
Require HTTPS in Production, with any insecure loopback development escape hatch explicit and unavailable by accident. Reject endpoint userinfo, query, and fragment components; vendor credentials belong only in Otlp:Headers. Log a sanitized destination that cannot carry secrets.
Any host-specific collector, TLS, CA, credential-delivery, or vendor wiring should be addressed separately in a private deploy/infra tracker.
Acceptance criteria
Blocked by
None. Actual collector and CA configuration, if needed, belongs in a private deploy/infra tracker.
Parent: #244
Epic: #15
Severity: Medium
Execution mode: AFK
What to build
Harden Otlp:Endpoint validation and startup logging. The app currently accepts plaintext HTTP endpoints and logs resolved endpoint URIs. A URI containing userinfo, query credentials, or sensitive tenant/vendor parameters could leak into console logs, while plaintext export exposes telemetry and authentication headers in transit.
Require HTTPS in Production, with any insecure loopback development escape hatch explicit and unavailable by accident. Reject endpoint userinfo, query, and fragment components; vendor credentials belong only in Otlp:Headers. Log a sanitized destination that cannot carry secrets.
Any host-specific collector, TLS, CA, credential-delivery, or vendor wiring should be addressed separately in a private deploy/infra tracker.
Acceptance criteria
Blocked by
None. Actual collector and CA configuration, if needed, belongs in a private deploy/infra tracker.