venkateshwaracholan commented on PR #4772:
URL: https://github.com/apache/polaris/pull/4772#issuecomment-4725448535

   @MonkeyCanCode Thanks for the feedback. I agree that keeping the redaction 
focused on the known credential exposure paths makes sense here.
   
   I've simplified the implementation to redact the Authorization header, fully 
redact `/oauth/tokens` request and response bodies, and only redact 
`client_secret`, `access_token`, and `refresh_token` in other JSON/form 
payloads. I also removed the broader sensitive-key list and realm-header 
heuristic, and updated the tests to match.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to