Skip to content

Keep hook commands out of the log - #40

Merged
chrisuthe merged 1 commit into
mainfrom
fix/hook-log-redaction
Aug 28, 2026
Merged

chrisuthe merged 1 commit into
mainfrom
fix/hook-log-redaction

Conversation

@chrisuthe

Copy link
Copy Markdown
Member

A hook command is an arbitrary shell line, so it routinely carries the one thing that must not be logged: a bearer token in a curl -H, a signed webhook URL, an API key in a query string. It was written to the log in full at DEBUG when spawned and reaped, and at WARN -- the default level -- whenever the hook failed, so an ordinary failing hook put the credential in the logfile, which under -f is a file on disk.

The event name and pid identify which hook a line is about, and the exit status or signal is the diagnosis; the command itself is already known to whoever configured it. The lines now carry event, pid and status, and the command is not logged at any level.

Fixes #35

A hook command is an arbitrary shell line, so it routinely carries the
one thing that must not be logged: a bearer token in a curl -H, a signed
webhook URL, an API key in a query string. It was written to the log in
full at DEBUG when spawned and reaped, and at WARN -- the default level
-- whenever the hook failed, so an ordinary failing hook put the
credential in the logfile, which under -f is a file on disk.

The event name and pid identify which hook a line is about, and the exit
status or signal is the diagnosis; the command itself is already known
to whoever configured it. The lines now carry event, pid and status, and
the command is not logged at any level.

Fixes #35
@chrisuthe
chrisuthe merged commit 184bb6a into main Aug 28, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hook commands are logged in full, including at WARN, so a token in one reaches the logfile

1 participant