Repository navigation
Wizard: stop logging the login code and GitHub's token response - #659
Conversation
LoginCode printed the OAuth code and the whole access-token response, which contains the admin's access token, to the server log. The second line was marked as debugging to remove. Closes #655. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is a minimal, self-contained removal of sensitive logging with no unused imports or broken references, and existing error handling is preserved.
Review effort: Balanced
Findings: None
What changed in this PR
This PR fixes a sensitive-data logging issue (#655) in the install wizard. Previously, wizard.LoginCode logged the OAuth login code and printed GitHub's entire access-token response—which contains the admin's access token—to stdout, ending up in docker logs and any downstream log aggregation. The PR removes both lines while keeping all error handling and control flow intact.
Changes:
- Remove
log.Println("LOGIN CODE: " + code)that logged the OAuth code. - Remove the
bodyString/fmt.Println("post:\n", ...)debug print (marked//todo: remove) that exposed the access-token response.
| File | Description |
|---|---|
| wizard/wizard.go | Removes two debug log statements that leaked the login code and the access-token response; bodyBytes and the log/fmt imports remain in use. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Closes #655.
wizard.LoginCodeprinted the OAuth code and GitHub's whole access-token response, which contains the admin's access token, to the server log (docker logsand wherever those are shipped). The second line was marked//todo: remove - just for debugging.Both lines are removed; nothing else used the values. Errors from the exchange are still returned and shown on the wizard page.
go test ./wizardpasses. The GitHub exchange itself has no test (see #654).🤖 Generated with Claude Code