-
Notifications
You must be signed in to change notification settings - Fork 93
Open
Description
Description
The JWT is always logged in internal microservice comms - this is a risk if Kibana is hacked or if a server engineer is corrupt
- Analyse QA log stream to find user details, JWT tokens and other pieces of information that are not critical for debugging but reveal too much information on the users of the system or records we store. Perform actions like creating a user, changing a password etc to see what the log output is.
- Use Pino to remove all of these details from the logs from any logs
Metadata
Metadata
Type
Projects
Status
No status