Skip to content

@cache: backend failure warnings log the raw query string #299

Description

@allen0099

Problem

When the backend fails, @cache logs the full cache key at WARNING (cache.py, "Cache backend read failed" and "Cache backend write failed"). The key contains the raw query string, so values such as ?token=..., ?code=... or an e-mail address end up in application logs, which are usually kept longer and read by more people than the cache itself.

#107 fixed the same problem for OAuth states by logging a short digest (_state_ref). The HTTP cache path was not changed.

Proposal

At WARNING and above, log the method and path plus a short SHA-256 digest of the key instead of the key itself. Keep the full key at DEBUG, where it is already logged, for local troubleshooting.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthttp-cacheThe @cache decorator, cache keys and Cache-Control handlingsecuritySecurity vulnerability or hardening

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions