Skip to content

security: stop logging code completion API keys - #94

Open
0PeterAdel wants to merge 3 commits into
linux-do:masterfrom
0PeterAdel:security/mask-api-key-logs
Open

0PeterAdel wants to merge 3 commits into
linux-do:masterfrom
0PeterAdel:security/mask-api-key-logs

Conversation

@0PeterAdel

@0PeterAdel 0PeterAdel commented Jul 8, 2026 •

Copy link
Copy Markdown

Summary

Stops logging code-completion API key material in getRandomApiKey. The selected key index remains available for diagnostics, while the selected key is returned unchanged for request authentication.

Security rationale

Partial masking still exposed the first and last four characters of long keys. Those fragments can aid credential correlation and provide unnecessary secret material in application logs. This change removes both full and partial key output.

Changes

  • Removes full and partially masked API key logging.
  • Preserves the non-secret selected-key index log.
  • Adds an automated stdout regression test for long and short keys.
  • Verifies that the full key, prefix, and suffix never appear in logs.
  • Verifies that key selection and return behavior remain unchanged.

Validation

Validated at commit 9171156fd91540e628e88d86f286865dec3b8db3 with Go 1.27.0 (module target: Go 1.21).

  • Added regression test file main_test.go is gofmt-clean.
  • Targeted security regression test passed.
  • Full race-enabled test suite passed: go test -race -count=1 ./....
  • Static analysis passed: go vet ./....
  • Trimmed-path build passed: go build -trimpath -o /tmp/override-pr94 ..
  • The old partial-masking commit fails the new test because its logged prefix and suffix are detected.
  • The current commit passes with no full or partial API key material in stdout.
  • Working tree was clean after validation.

@0PeterAdel 0PeterAdel changed the title security: Avoid logging full code completion API keys security: stop logging code completion API keys Aug 28, 2026
@0PeterAdel

Copy link
Copy Markdown
Author

Security validation evidence

Validated commit 9171156fd91540e628e88d86f286865dec3b8db3 against upstream/master at 8603e7429e00426b9aa4d26105b4343d92139aae.

Check Result
PR head verification PASS
Added regression test formatting PASS — main_test.go is gofmt-clean
Old partial-mask implementation PASS — rejected because logged key fragments were detected
Current full/partial key exposure PASS — no key material emitted
Targeted security regression PASS
Race-enabled test suite PASS
go vet ./... PASS
Trimmed-path build PASS
Repository state PASS — clean

The regression test confirms the behavioral difference directly: the previous partial-masking implementation fails because key prefixes and suffixes reach stdout, while the current implementation returns the selected key without logging any full or partial key material. The non-secret selected-key index remains available for diagnostics.

screenshot-2026-08-28_05-57-23

@ahmad-maxai

Copy link
Copy Markdown

Hello everyone , I’d like to join the LINUX DO community. I’m ahmad-maxai(https://github.com/ahmad-maxai). If anyone with premium / Trust Level 3 can share the invite link or tag a moderator who can help, I’d really appreciate it asaidtanko@gmail.com.

@binancarg86-sudo

Copy link
Copy Markdown

Hi everyone,

I hope you're all doing well! I'm reaching out here because I'm currently working on a really important software project—a fitness application called OmniFit that heavily integrates AI API endpoints—and I was highly recommended to check out the tools and API gateways (like AIPM) shared within the LINUX DO community.

I've been looking for reliable AI access to finish testing my application builds, and I'd also love to learn from and participate in the community discussions. Since registrations are currently invite-only, I was wondering if any Level 3 member would be kind enough to share an invitation code with me.

My email is: binancarg86@gmail.com

I would truly appreciate the help, and I look forward to hopefully being part of the forum. Thanks in advance for your time!

Best regards.

@0PeterAdel

Copy link
Copy Markdown
Author

Hi @zhuiyue132, could you please take a look when you have time?

I could not find a CONTRIBUTING.md or CODEOWNERS file in this repository, so I am leaving a concise review ping here. This PR is still mergeable and has no unresolved review threads.

What changed:

  • Stops logging full or partially masked code-completion API keys.
  • Keeps the non-secret selected-key index log for diagnostics.
  • Adds a regression test that fails against the previous partial-mask behavior and passes with no full/prefix/suffix key material in stdout.
  • Validation already posted above: targeted test, full race-enabled test suite, go vet ./..., and trimmed-path build all passed.

Happy to adjust the patch if you prefer a different logging behavior or test shape.

@0PeterAdel

Copy link
Copy Markdown
Author

Hi @zhuiyue132 and LINUX DO maintainers,

Alongside this security PR, I would also like to join the LINUX DO community if possible.

I am not only asking for an invite link casually; I am trying to contribute in a useful way first. This PR removes code-completion API key material from logs, adds a regression test, and includes validation evidence so the change is easy to review. I would like to keep contributing, discuss technical/security improvements with the community, and follow the right community process.

If someone with the right permission can invite me, or if a moderator can point me to the correct path, I would really appreciate it.

Email: 1peteradel@gmail.com

Thank you for maintaining the project and the community.

@0PeterAdel

Copy link
Copy Markdown
Author

Hi @wozulong & @zhuiyue132 and maintainers,

Could you please help review this security PR? It removes API key material from logs and adds a regression test; validation evidence is posted above.

The Docker workflow is currently waiting for maintainer approval:
https://github.com/linux-do/override/actions/runs/36764160186

Could someone with write access click Approve workflows to run?

The fresh run uses an empty commit with the same tree as the validated patch; no code changes were introduced.

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants