From d3dde3609db20e8f5086d1cb4311db6f70cf6854 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:09:03 +0200 Subject: [PATCH] fix: audit log records new passwords in plain text (#31622) With request auditing turned on, the audit log only masked fields named exactly "password". The new password from a password change, and passwords entered in admin settings such as YaCy or Jupyter, were written to the log as-is. Any field whose name ends in "password", in any letter case, is now replaced with asterisks. --- backend/open_webui/utils/audit.py | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/backend/open_webui/utils/audit.py b/backend/open_webui/utils/audit.py index 7354b2c641..177036acb6 100644 --- a/backend/open_webui/utils/audit.py +++ b/backend/open_webui/utils/audit.py @@ -282,11 +282,12 @@ class AuditLoggingMiddleware: response_body = context.response_body.decode('utf-8', errors='replace') # Redact sensitive information - if 'password' in request_body: + if 'password' in request_body.lower(): request_body = re.sub( - r'"password":\s*"(.*?)"', - '"password": "********"', + r'"(\w*password)":\s*".*?"', + r'"\1": "********"', request_body, + flags=re.IGNORECASE, ) entry = AuditLogEntry(