navidrome/log
Deluan Quintão 46c432719f
fix(log): redact LastFM keys and Prometheus password in config dump (#6233)
The startup Configuration dump is rendered with pretty.Sprintf("%# v"), which
pads multi-line struct fields with spaces after the colon. The ApiKey and
Secret redaction patterns required the quote right after the colon, so
LastFM.ApiKey and LastFM.Secret were logged in clear text even with
EnableLogRedacting on. Allow optional whitespace after the colon, like the
other config patterns already do.

Prometheus.Password had no redaction pattern at all. Add one that also skips
escaped quotes, since the password can hold any character and pretty prints
it Go-quoted.

Add tests for the padded and unpadded forms, plus one that redacts a real
pretty.Sprintf dump of LastFM- and Prometheus-shaped structs so a padding
change in pretty can't bring the leak back.

Reported in https://github.com/navidrome/navidrome/discussions/6232
2026-09-26 23:30:50 -04:00
..
formatters.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
formatters_test.go feat(artwork): new artwork pipeline with background resolution and Low Quality Image Placeholders (#5847) 2026-08-09 15:03:27 -04:00
journal.go chore: go fix 2026-05-28 22:13:05 -03:00
journal_test.go feat(server): add syslog priority prefixes for systemd-journald (#5192) 2026-03-15 14:14:05 -04:00
log.go fix(log): redact LastFM keys and Prometheus password in config dump (#6233) 2026-09-26 23:30:50 -04:00
log_test.go fix(log): redact LastFM keys and Prometheus password in config dump (#6233) 2026-09-26 23:30:50 -04:00
redactrus.go feat(plugins): experimental support for plugins (#3998) 2025-06-22 20:45:38 -04:00
redactrus_test.go Reverse proxy authentication support (#1152) 2021-06-11 23:17:21 -04:00