Part of the ARC-OSC workboard triage track.
What's needed
Audit what the client currently logs (console, files, telemetry) and decide policy for credentials / PII: what must never be logged, what gets redacted, and what gets a warning if present.
Scope
- Inventory current logging surfaces (main process, renderer, preload)
- Define redaction rules for credentials, tokens, session cookies, and user identifiers
- Decide where audit-worthy events (auth failures, reconnects, permission changes) should be recorded
Acceptance criteria
Out of scope: implementing redaction (separate issue after triage).
Part of the ARC-OSC workboard triage track.
What's needed
Audit what the client currently logs (console, files, telemetry) and decide policy for credentials / PII: what must never be logged, what gets redacted, and what gets a warning if present.
Scope
Acceptance criteria
Out of scope: implementing redaction (separate issue after triage).