Skip to content

Hide homeserver token from aiohttp logs #351

Closed as not planned
Closed as not planned
@pacien

Description

@pacien

By default, the aiohttp logger is set to the INFO level, which causes all HTTP requests to be logged with the appservice's token in them. This might be a security issue.

For reference, Synapse redacts all tokens when logging requests.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or improvementexternalThis issue is valid, but needs to be fixed somewhere else (e.g. a library)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions