Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-6886

Provide ability to prevent logging of service tokens/user keys in 3scale-istio-adapter

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • None
    • Istio Integration
    • False
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Undefined

      There is an expectation that proxies will not log information sent as headers.  However, in the case of the 3scale-istio-adapter, the user_key is logged in the event of an error calling the 3scale backend. This is true regardless of whether the user_key was sent via query parameter or header. The log also includes the API service token which is sensitive information.

      There is currently no way to suppress this information from being logged.

       

            Unassigned Unassigned
            rhn-support-spoole Shannon Poole
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: