-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Exclude IP #295
Comments
Which field are you referring to? |
|
|
This is the way I'm using acra. I didn't include an IP knowingly. |
Hmm, then that's very strange. The only place that USER_IP is included is https://github.com/ACRA/acra/blob/master/src/main/java/org/acra/collector/CrashReportDataFactory.java#L502 Can you post a crash report created from that config, showing it. |
This is from my device. |
None of the lowercase fields in that report are ACRA fields, including |
I dont fully understand this. So it is acralyzer that saves these values to the log? |
ACRA is the client side library. It is not adding these fields. The HttpRequest that ACRA is using to send to your back end (presumably ACRAlyzer) may well be adding these fields to the report. ACRAlyzer (which I don't know a lot about) should just be logging the incoming request and aggregating it. |
Try recompiling ACRA with I suspect that it is clean and that those fields are being added afterwards by the Apache HttpClient. |
I didn't configure anything for acralyzer. So this is a serious privacy leaking by acralyer? So I should file a bug there? |
Well I don't think it's serious privacy leak. Every http call to a server But if you don't want it recorded on the server then, yes the server would Personally I think your fears are misplaced. On Wed, 29 Jul 2015 3:52 am Paul Woitaschek notifications@github.com
|
Thanks for the reply. I wouldn't personally care too much about this, but I state for the users of my app, that all data is recorded anonymously, so I would prefer to collect as less data as I can. (especially for data I don't need). |
Is it possible to only exclude the ip from bug reports? I can see them on every report and I feel this is something private.
The text was updated successfully, but these errors were encountered: