Keep hook commands out of the log - #40
Merged
Merged
Conversation
A hook command is an arbitrary shell line, so it routinely carries the one thing that must not be logged: a bearer token in a curl -H, a signed webhook URL, an API key in a query string. It was written to the log in full at DEBUG when spawned and reaped, and at WARN -- the default level -- whenever the hook failed, so an ordinary failing hook put the credential in the logfile, which under -f is a file on disk. The event name and pid identify which hook a line is about, and the exit status or signal is the diagnosis; the command itself is already known to whoever configured it. The lines now carry event, pid and status, and the command is not logged at any level. Fixes #35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A hook command is an arbitrary shell line, so it routinely carries the one thing that must not be logged: a bearer token in a curl -H, a signed webhook URL, an API key in a query string. It was written to the log in full at DEBUG when spawned and reaped, and at WARN -- the default level -- whenever the hook failed, so an ordinary failing hook put the credential in the logfile, which under -f is a file on disk.
The event name and pid identify which hook a line is about, and the exit status or signal is the diagnosis; the command itself is already known to whoever configured it. The lines now carry event, pid and status, and the command is not logged at any level.
Fixes #35