Skip to content

Commit e6d6789

Browse files
authored
Stop logging full access token secret (#321)
Note that the log was truncated before any token was exposed.
1 parent e13fe12 commit e6d6789

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

controllers/gitrepo/steps.go

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -189,7 +189,11 @@ func ensureAccessToken(ctx context.Context, cli client.Client, instance *synv1al
189189
if err != nil {
190190
return fmt.Errorf("error creating or updating access token secret: %w", err)
191191
}
192-
log.FromContext(ctx).Info("Reconciled secret", "secret", secret, "op", op)
192+
log.FromContext(ctx).Info("Reconciled secret",
193+
"secret", secret.Name,
194+
"pat_uid", secret.Annotations[LieutenantAccessTokenUIDAnnotation],
195+
"pat_expires_at", secret.Annotations[LieutenantAccessTokenExpiresAtAnnotation],
196+
"op", op)
193197

194198
return nil
195199
}

0 commit comments

Comments
 (0)