Skip to content

[Feature] Add #[SensitiveParameter] attribute for sensitive data protection #777

Description

@jeshtan

Our external pentest team had identified the exposure of ldap password in stack traces and logs.

Could you adding `#[SensitiveParameter] attribute to method parameters that contain sensitive information to migrating security risk?

Thanks.

Activity

  1. self-assigned this
    on Aug 13, 2025
  2. stevebauman commented on Aug 13, 2025

    @stevebauman
    Member

    Thanks for the report @jeshtan. I'll add this now.

  3. jeshtan commented on Sep 10, 2025

    @jeshtan
    Author

    @stevebauman Thanks for your effort. The #778 PR works as expected. Hope can see it get merged soon :)

  4. stevebauman commented on Dec 13, 2025

    @stevebauman
    Member

    Hi @jeshtan just an update on this -- I'm going to wait until January 2026 to merge the PR in as PHP 8.1 is still supported with security updates til December 31st, 2025: https://www.php.net/supported-versions.php. These security annotations are only available in 8.2, so I want to continue supporting 8.1 until PHP themselves drop support 👍

  5. cheesegrits commented on Apr 26, 2026

    @cheesegrits
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions