Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(cli): improve provider resolution outputs and remove sensitive information from debug logs #418

Merged
merged 24 commits into from
Sep 27, 2023

Conversation

FuzzB0t
Copy link
Contributor

@FuzzB0t FuzzB0t commented Sep 9, 2023

No description provided.

@nx-cloud
Copy link

nx-cloud bot commented Sep 9, 2023

☁️ Nx Cloud Report

CI is running/has finished running commands for commit 2a9b3ae. As they complete they will appear below. Click to see the status, the terminal output, and the build insights.

📂 See all runs for this branch


✅ Successfully ran 1 target

Sent with 💌 from NxCloud.

@FuzzB0t FuzzB0t changed the title Provider resolution bug fix(cli): improve provider resolution outputs & remove sensitive information from debug logs Sep 9, 2023
@FuzzB0t FuzzB0t linked an issue Sep 9, 2023 that may be closed by this pull request
@FuzzB0t
Copy link
Contributor Author

FuzzB0t commented Sep 9, 2023

Changes in this PR:

  • Remove check for private key when selecting which registryProviderUrl to use.
  • Add better user facing logs to registry provider url selection.
  • Remove Private key and Cannon directory from debug logs.

debug('got settings', finalSettings);
// Filter out private key for logging
/* eslint-disable @typescript-eslint/no-unused-vars */
const { cannonDirectory, privateKey, ...filteredSettings } = finalSettings;
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  1. Provider ur contains api key
  2. Afaik many other places log full path and expose username

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch thanks for the feedback @noisekit!

Copy link
Contributor

@noisekit noisekit Sep 12, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also publishIpfsUrl contains auth in the url

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ideally those values not excluded from logs but replaced with smth like ****

@FuzzB0t FuzzB0t changed the title fix(cli): improve provider resolution outputs & remove sensitive information from debug logs fix(cli): improve provider resolution outputs and remove sensitive information from debug logs Sep 14, 2023
@FuzzB0t FuzzB0t marked this pull request as draft September 14, 2023 19:15
@FuzzB0t FuzzB0t self-assigned this Sep 14, 2023
@FuzzB0t FuzzB0t marked this pull request as ready for review September 16, 2023 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Fix bug in provider resolution process and add better logs
2 participants