Skip to content

Redact password arguments from exception traces - #778

Merged
stevebauman merged 6 commits into
masterfrom
task-777
Oct 8, 2026
Merged

stevebauman merged 6 commits into
masterfrom
task-777

Conversation

@stevebauman

@stevebauman stevebauman commented Aug 13, 2025 •

Copy link
Copy Markdown
Member

LDAP passwords can appear in exception traces when authentication, password assignment, or a password change fails.

I've added #[SensitiveParameter] to password arguments, including the newer OpenLDAP and Argon2 APIs. I've also covered authentication events and the model input methods that forward passwords, since annotating only the password mutator still leaves the value visible in earlier frames. Model attribute values and arrays are redacted in full.

PHP 8.1 remains supported. Native parameter redaction takes effect on PHP 8.2 and newer.

Validated with the existing unit suite on PHP 8.4 and PHP 8.1, and Pint.

Closes #777.

@stevebauman stevebauman changed the title [Feature] Add #[SensitiveParameter] attribute for sensitive data protection Redact password arguments from exception traces Oct 5, 2026
@stevebauman
stevebauman merged commit c2fedca into master Oct 8, 2026
31 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature] Add #[SensitiveParameter] attribute for sensitive data protection

1 participant