Skip to content

Maps: Redact API credentials from debug logging - #3814

Open
paulcakeface wants to merge 1 commit into
microg:masterfrom
paulcakeface:paul/maps-api-token-log-privacy
Open

paulcakeface wants to merge 1 commit into
microg:masterfrom
paulcakeface:paul/maps-api-token-log-privacy

Conversation

@paulcakeface

Copy link
Copy Markdown

Summary

Avoid logging credential-bearing request and response values in the Maps ApiTokenService.

requestApiToken currently logs the complete incoming parameter Bundle. This bundle contains the API_KEY value used to construct the Maps API token request.

On a successful request, the service also logs the complete CreateAndroidApiTokenResponse, which contains the returned apiToken.

This change replaces those value-bearing logs with bounded diagnostic messages while retaining the request-stage and success information useful for debugging.

Changes

  • Stop logging the complete requestApiToken parameter bundle
  • Stop logging the complete successful API token response
  • Retain the request thread information and success-stage diagnostics

There are no changes to API key handling, token request construction, returned token data, expiry handling, error handling or control flow.

Validation

The branch is based directly on current upstream master:

4c74e5acb79479004428be755547432294639878

Exact validated commit:

2a30619cb257b6f61cb5cf321bb96bfc5b67ea63

GitHub Actions validation completed successfully:

  • Debug assemble: PASS
  • Debug lint: PASS
  • Release assemble: PASS
  • Release lint: PASS

git diff --check also passes.

The resulting commit changes one source file with two additions and two deletions.

No physical-device testing was required or performed because this change only alters diagnostic logging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant