@@ -380,7 +380,9 @@ pub struct AppLoggingConfig {
380380 /// Allowed values: trace, debug, info, warn, error, off.
381381 pub level : String ,
382382 /// Whether diagnostic logs may include sensitive troubleshooting payloads.
383- #[ serde( default = "default_true" ) ]
383+ /// Off by default, matching the settings UI copy ("Off by default") and the
384+ /// privacy guidance in the capability docs (#3213).
385+ #[ serde( default ) ]
384386 pub include_sensitive_diagnostics : bool ,
385387 /// Whether the local UI records detailed Flow Chat viewport diagnostics.
386388 #[ serde( default ) ]
@@ -1908,7 +1910,8 @@ impl Default for AppLoggingConfig {
19081910 Self {
19091911 // Set to Debug in early development for easier diagnostics
19101912 level : "debug" . to_string ( ) ,
1911- include_sensitive_diagnostics : true ,
1913+ // Off by default: sensitive payloads are opt-in (#3213)
1914+ include_sensitive_diagnostics : false ,
19121915 flow_chat_diagnostics : false ,
19131916 model_exchange_tracing : ModelExchangeTracingConfig :: default ( ) ,
19141917 }
@@ -3469,13 +3472,13 @@ mod tests {
34693472 }
34703473
34713474 #[ test]
3472- fn app_logging_defaults_to_sensitive_diagnostics_enabled ( ) {
3475+ fn app_logging_defaults_to_sensitive_diagnostics_disabled ( ) {
34733476 let config: AppLoggingConfig = serde_json:: from_value ( serde_json:: json!( {
34743477 "level" : "trace"
34753478 } ) )
34763479 . expect ( "logging config without sensitive preference should deserialize" ) ;
34773480
3478- assert ! ( config. include_sensitive_diagnostics) ;
3481+ assert ! ( ! config. include_sensitive_diagnostics) ;
34793482 assert ! ( !config. flow_chat_diagnostics) ;
34803483 assert_eq ! (
34813484 config. model_exchange_tracing. mode,
0 commit comments