Skip to content

Bot token leaks to logs #36

Open
Open
@vsushkov

Description

@vsushkov

Looking at logs of my service I've noticed bot token is getting written to the log files. Which is not quite secure.

Example of the log:

level=error msg="Failed to get updates, retrying in 3 seconds ..." err="cannot get events: error while making request: cannot make request to bot api: Get \"https://api.internal.myteam.mail.ru/bot/v1//events/get?lastEventId=86&pollTime=60&token=123.123123123.123123%3A123123123\": context canceled" retry interval="3 seconds"

The token is a URL parameter, and the URL gets logged here:

return []byte{}, fmt.Errorf("cannot make request to bot api: %s", err)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions