Skip to content

sql: print out statements in logs with redaction markers only around sensitive bits (make SQL keywords etc non-redactable) #65401

@pxlogan

Description

@pxlogan

Is your feature request related to a problem? Please describe.
Currently in the SQL Audit logs AWS secret keys are fully displayed when they are logged. Even though these can be redacted when extracted it is bad behaviour to have these logged ever.

Describe the solution you'd like
No secret keys/similar displayed in logs ever,

Describe alternatives you've considered
None

Additional context

Epic CC-4113

Metadata

Metadata

Assignees

Labels

A-loggingIn and around the logging infrastructure.A-securityA-sql-observabilityRelated to observability of the SQL layerA-sql-syntaxIssues strictly related to the SQL grammar, with no semantic aspectC-enhancementSolution expected to add code/behavior + preserve backward-compat (pg compat issues are exception)

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions