Update logging to redact AccessToken if provided at commandline #50
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
All API accessing methods allow users to provide an AccessToken to be used
for the duration of that API call. The problem with that is that the
command is also logged by default, which means that the AccessToken value
might be logged in plain text to the log file.
To fix this,
Write-InvocationLog
has been modified in a few ways:AccessToken
has been configured to always be redacted, andNoStatus
has been configured to always be excluded (to avoid noise)values of the parameters, this now logs a single line with a modified version
of the invocation with the substitution of parameter values performed in-place.
DisableParameterLogging
configuation value has been removed, as we're nolonger taking up additional verbose space (we're always logging a single line), and
we have to process the parameters anyway to ensure that we're excluding/redacting
the necessary parameters, meaning that we can't log the invoked line no matter what.