Skip to content

Commit 8e20002

Browse files
committed
fix(icaptcha-client): do not log raw ICAPTCHA_INSECURE value
The non-truthy warn path previously recorded the full trimmed env value. That is arbitrary deployment input; report only that the setting is invalid (#246 review).
1 parent 7d218ac commit 8e20002

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

  • crates/icaptcha-client/src

‎crates/icaptcha-client/src/lib.rs‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -105,8 +105,9 @@ fn icaptcha_insecure_enabled() -> bool {
105105
true
106106
} else {
107107
if !t.is_empty() {
108+
// Do not log the raw env value: it is arbitrary deployment
109+
// input and may contain secrets or terminal controls (#246).
108110
tracing::warn!(
109-
value = %t,
110111
"GITLAWB_ICAPTCHA_INSECURE is set but not truthy (expected 1 or true); \
111112
loopback HTTP trust relaxation remains disabled"
112113
);

0 commit comments

Comments
 (0)