Skip to content

Commit 034342e

Browse files
committed
fix(config): default sensitive diagnostics to off, matching the UI copy
1 parent 66e8abd commit 034342e

5 files changed

Lines changed: 39 additions & 9 deletions

File tree

‎src/crates/adapters/ai-adapters/src/diagnostics.rs‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
use std::sync::atomic::{AtomicBool, Ordering};
22

3-
static INCLUDE_SENSITIVE_DIAGNOSTICS: AtomicBool = AtomicBool::new(true);
3+
// Fail closed until the config layer applies the saved preference (#3213):
4+
// sensitive diagnostics are opt-in everywhere else (config default, UI copy).
5+
static INCLUDE_SENSITIVE_DIAGNOSTICS: AtomicBool = AtomicBool::new(false);
46

57
pub fn set_include_sensitive_diagnostics(enabled: bool) {
68
INCLUDE_SENSITIVE_DIAGNOSTICS.store(enabled, Ordering::Relaxed);

‎src/crates/contracts/config-contracts/src/types.rs‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -380,7 +380,9 @@ pub struct AppLoggingConfig {
380380
/// Allowed values: trace, debug, info, warn, error, off.
381381
pub level: String,
382382
/// Whether diagnostic logs may include sensitive troubleshooting payloads.
383-
#[serde(default = "default_true")]
383+
/// Off by default, matching the settings UI copy ("Off by default") and the
384+
/// privacy guidance in the capability docs (#3213).
385+
#[serde(default)]
384386
pub include_sensitive_diagnostics: bool,
385387
/// Whether the local UI records detailed Flow Chat viewport diagnostics.
386388
#[serde(default)]
@@ -1908,7 +1910,8 @@ impl Default for AppLoggingConfig {
19081910
Self {
19091911
// Set to Debug in early development for easier diagnostics
19101912
level: "debug".to_string(),
1911-
include_sensitive_diagnostics: true,
1913+
// Off by default: sensitive payloads are opt-in (#3213)
1914+
include_sensitive_diagnostics: false,
19121915
flow_chat_diagnostics: false,
19131916
model_exchange_tracing: ModelExchangeTracingConfig::default(),
19141917
}
@@ -3469,13 +3472,13 @@ mod tests {
34693472
}
34703473

34713474
#[test]
3472-
fn app_logging_defaults_to_sensitive_diagnostics_enabled() {
3475+
fn app_logging_defaults_to_sensitive_diagnostics_disabled() {
34733476
let config: AppLoggingConfig = serde_json::from_value(serde_json::json!({
34743477
"level": "trace"
34753478
}))
34763479
.expect("logging config without sensitive preference should deserialize");
34773480

3478-
assert!(config.include_sensitive_diagnostics);
3481+
assert!(!config.include_sensitive_diagnostics);
34793482
assert!(!config.flow_chat_diagnostics);
34803483
assert_eq!(
34813484
config.model_exchange_tracing.mode,

‎src/web-ui/src/infrastructure/config/services/FrontendLogLevelSync.test.ts‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,4 +99,27 @@ describe('FrontendLogLevelSync startup reads', () => {
9999
expect(loggerMocks.setIncludeSensitiveDiagnostics).toHaveBeenCalledWith(true);
100100
expect(loggerMocks.setFlowChatDiagnosticsEnabled).toHaveBeenCalledWith(false);
101101
});
102+
103+
it('defaults sensitive diagnostics to off when no saved preference exists (#3213)', async () => {
104+
configApiMocks.getConfigs.mockResolvedValueOnce({
105+
[LOGGING_LEVEL_PATH]: 'warn',
106+
});
107+
configApiMocks.getRuntimeLoggingInfo.mockResolvedValueOnce({ effectiveLevel: 'warn' });
108+
109+
const { initializeFrontendLogLevelSync } = await importSyncModule();
110+
await initializeFrontendLogLevelSync();
111+
112+
expect(loggerMocks.setIncludeSensitiveDiagnostics).toHaveBeenCalledWith(false);
113+
});
114+
115+
it('falls back to runtime info with sensitive diagnostics off when no saved preference exists (#3213)', async () => {
116+
configApiMocks.getConfigs.mockResolvedValueOnce({});
117+
configApiMocks.getRuntimeLoggingInfo.mockResolvedValueOnce({ effectiveLevel: 'error' });
118+
119+
const { initializeFrontendLogLevelSync } = await importSyncModule();
120+
await initializeFrontendLogLevelSync();
121+
122+
expect(loggerMocks.setLevel).toHaveBeenCalledWith(4);
123+
expect(loggerMocks.setIncludeSensitiveDiagnostics).toHaveBeenCalledWith(false);
124+
});
102125
});

‎src/web-ui/src/infrastructure/config/services/FrontendLogLevelSync.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ async function resolveInitialLoggingSettings(): Promise<InitialLoggingSettings>
102102
includeSensitiveDiagnostics:
103103
typeof configs[LOGGING_INCLUDE_SENSITIVE_PATH] === 'boolean'
104104
? configs[LOGGING_INCLUDE_SENSITIVE_PATH]
105-
: true,
105+
: false,
106106
flowChatDiagnostics: configs[FLOW_CHAT_DIAGNOSTICS_PATH] === true,
107107
};
108108
}
@@ -115,7 +115,7 @@ async function resolveInitialLoggingSettings(): Promise<InitialLoggingSettings>
115115
includeSensitiveDiagnostics:
116116
typeof configs[LOGGING_INCLUDE_SENSITIVE_PATH] === 'boolean'
117117
? configs[LOGGING_INCLUDE_SENSITIVE_PATH]
118-
: true,
118+
: false,
119119
flowChatDiagnostics: configs[FLOW_CHAT_DIAGNOSTICS_PATH] === true,
120120
};
121121
}
@@ -125,7 +125,7 @@ async function resolveInitialLoggingSettings(): Promise<InitialLoggingSettings>
125125
includeSensitiveDiagnostics:
126126
typeof configs[LOGGING_INCLUDE_SENSITIVE_PATH] === 'boolean'
127127
? configs[LOGGING_INCLUDE_SENSITIVE_PATH]
128-
: true,
128+
: false,
129129
flowChatDiagnostics: configs[FLOW_CHAT_DIAGNOSTICS_PATH] === true,
130130
};
131131
}

‎src/web-ui/src/shared/utils/logger.ts‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,9 @@ const isTauri = typeof window !== 'undefined' && '__TAURI__' in window;
3434
const isDev = import.meta.env?.DEV ?? process.env.NODE_ENV === 'development';
3535

3636
const CONSOLE_FORWARD_INSTALLED = '__openbitfun_console_forward_installed__';
37-
let includeSensitiveDiagnostics = true;
37+
// Off until the saved preference is loaded (#3213): the settings UI and the
38+
// backend config both default sensitive diagnostics to disabled.
39+
let includeSensitiveDiagnostics = false;
3840

3941
declare global {
4042
// Injected by the desktop WebView initialization script before the frontend bundle runs.

0 commit comments

Comments
 (0)