cds-snc / covid-alert-server

Exposure Notification: Diagnosis Server implementation / Notification d’exposition : Mise en œuvre du serveur de diagnostic
Apache License 2.0
298 stars 31 forks source link

Remove header from logging #219

Closed maxneuvians closed 4 years ago

maxneuvians commented 4 years ago

When the code determined a Hash ID was used, the code would log the entire header including the bearer token, this could have led to a disclosure of the Bearer tokens through logs.