fix: audit log records new passwords in plain text (#31622)

With request auditing turned on, the audit log only masked fields named exactly "password". The new password from a password change, and passwords entered in admin settings such as YaCy or Jupyter, were written to the log as-is. Any field whose name ends in "password", in any letter case, is now replaced with asterisks.
This commit is contained in:
Classic298 2026-09-30 17:09:03 +02:00 • committed by GitHub
parent b4ebd0d62f
commit d3dde3609d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -282,11 +282,12 @@ class AuditLoggingMiddleware:
response_body = context.response_body.decode('utf-8', errors='replace')
# Redact sensitive information
if 'password' in request_body:
if 'password' in request_body.lower():
request_body = re.sub(
r'"password":\s*"(.*?)"',
'"password": "********"',
r'"(\w*password)":\s*".*?"',
r'"\1": "********"',
request_body,
flags=re.IGNORECASE,
)
entry = AuditLogEntry(