Skip to content

Commit e509a21

Browse files
Potential fix for pull request finding 'CodeQL / Cleartext logging of sensitive information'
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
1 parent 109c929 commit e509a21

File tree

1 file changed

+2
-3
lines changed
  • crates/trusted-server-core/src/ec

1 file changed

+2
-3
lines changed

crates/trusted-server-core/src/ec/kv.rs

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -631,7 +631,7 @@ impl KvIdentityGraph {
631631

632632
let Some(domain) = validated_stored_domain(domain) else {
633633
log::warn!(
634-
"update_last_seen: skipping invalid publisher domain for '{}': '{domain}'",
634+
"update_last_seen: skipping invalid publisher domain for '{}'",
635635
log_id(ec_id),
636636
);
637637
return Ok(());
@@ -658,10 +658,9 @@ impl KvIdentityGraph {
658658
);
659659
} else {
660660
// log_id() truncates the EC ID — safe for logging.
661-
// lgtm[rust/cleartext-logging] -- false positive: only the redacted 8-char prefix is logged.
662661
log::debug!(
663662
"update_last_seen: seen_domains cap ({MAX_SEEN_DOMAINS}) reached \
664-
for '{}', dropping domain '{domain}'",
663+
for '{}', dropping additional domain",
665664
log_id(ec_id),
666665
);
667666
}

0 commit comments

Comments
 (0)