Skip to content

Triage: audit logging for credential / PII leakage #53

Description

@ComfyChloe

Part of the ARC-OSC workboard triage track.

What's needed

Audit what the client currently logs (console, files, telemetry) and decide policy for credentials / PII: what must never be logged, what gets redacted, and what gets a warning if present.

Scope

  • Inventory current logging surfaces (main process, renderer, preload)
  • Define redaction rules for credentials, tokens, session cookies, and user identifiers
  • Decide where audit-worthy events (auth failures, reconnects, permission changes) should be recorded

Acceptance criteria

  • Written triage decision covering what is logged, redacted, or forbidden
  • Follow-up implementation issue(s) created from the decision

Out of scope: implementing redaction (separate issue after triage).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Priority: LowCan wait before others with high priorityStatus: Needs TriageNeeds review to determine priority and ownership

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions