Problem
When the backend fails, @cache logs the full cache key at WARNING (cache.py, "Cache backend read failed" and "Cache backend write failed"). The key contains the raw query string, so values such as ?token=..., ?code=... or an e-mail address end up in application logs, which are usually kept longer and read by more people than the cache itself.
#107 fixed the same problem for OAuth states by logging a short digest (_state_ref). The HTTP cache path was not changed.
Proposal
At WARNING and above, log the method and path plus a short SHA-256 digest of the key instead of the key itself. Keep the full key at DEBUG, where it is already logged, for local troubleshooting.
Problem
When the backend fails,
@cachelogs the full cache key at WARNING (cache.py, "Cache backend read failed" and "Cache backend write failed"). The key contains the raw query string, so values such as?token=...,?code=...or an e-mail address end up in application logs, which are usually kept longer and read by more people than the cache itself.#107 fixed the same problem for OAuth states by logging a short digest (
_state_ref). The HTTP cache path was not changed.Proposal
At WARNING and above, log the method and path plus a short SHA-256 digest of the key instead of the key itself. Keep the full key at DEBUG, where it is already logged, for local troubleshooting.