MonkeyCanCode commented on PR #4772: URL: https://github.com/apache/polaris/pull/4772#issuecomment-4725679283
> @MonkeyCanCode Thanks for the feedback. Keeping the redaction focused on the known credential exposure paths makes sense here.. > > > > I've simplified the implementation to redact the Authorization header, fully redact `/oauth/tokens` request and response bodies, and only redact `client_secret`, `access_token`, and `refresh_token` in other JSON/form payloads. I also removed the broader sensitive-key list and realm-header heuristic, and updated the tests to match. > > Thanks. I will take a look tomorrow. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
