security: stop logging code completion API keys - #94
0PeterAdel wants to merge 3 commits into
Conversation
|
Hello everyone , I’d like to join the LINUX DO community. I’m ahmad-maxai(https://github.com/ahmad-maxai). If anyone with premium / Trust Level 3 can share the invite link or tag a moderator who can help, I’d really appreciate it asaidtanko@gmail.com. |
|
Hi everyone, I hope you're all doing well! I'm reaching out here because I'm currently working on a really important software project—a fitness application called OmniFit that heavily integrates AI API endpoints—and I was highly recommended to check out the tools and API gateways (like AIPM) shared within the LINUX DO community. I've been looking for reliable AI access to finish testing my application builds, and I'd also love to learn from and participate in the community discussions. Since registrations are currently invite-only, I was wondering if any Level 3 member would be kind enough to share an invitation code with me. My email is: binancarg86@gmail.com I would truly appreciate the help, and I look forward to hopefully being part of the forum. Thanks in advance for your time! Best regards. |
|
Hi @zhuiyue132, could you please take a look when you have time? I could not find a What changed:
Happy to adjust the patch if you prefer a different logging behavior or test shape. |
|
Hi @zhuiyue132 and LINUX DO maintainers, Alongside this security PR, I would also like to join the LINUX DO community if possible. I am not only asking for an invite link casually; I am trying to contribute in a useful way first. This PR removes code-completion API key material from logs, adds a regression test, and includes validation evidence so the change is easy to review. I would like to keep contributing, discuss technical/security improvements with the community, and follow the right community process. If someone with the right permission can invite me, or if a moderator can point me to the correct path, I would really appreciate it. Email: 1peteradel@gmail.com Thank you for maintaining the project and the community. |
|
Hi @wozulong & @zhuiyue132 and maintainers, Could you please help review this security PR? It removes API key material from logs and adds a regression test; validation evidence is posted above. The Docker workflow is currently waiting for maintainer approval: Could someone with write access click Approve workflows to run? The fresh run uses an empty commit with the same tree as the validated patch; no code changes were introduced. Thank you! |

Summary
Stops logging code-completion API key material in
getRandomApiKey. The selected key index remains available for diagnostics, while the selected key is returned unchanged for request authentication.Security rationale
Partial masking still exposed the first and last four characters of long keys. Those fragments can aid credential correlation and provide unnecessary secret material in application logs. This change removes both full and partial key output.
Changes
Validation
Validated at commit
9171156fd91540e628e88d86f286865dec3b8db3with Go 1.27.0 (module target: Go 1.21).main_test.gois gofmt-clean.go test -race -count=1 ./....go vet ./....go build -trimpath -o /tmp/override-pr94 ..