-
Notifications
You must be signed in to change notification settings - Fork 54
LCORE-503: Don't log sensitive info #455
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
LCORE-503: Don't log sensitive info #455
Conversation
WalkthroughSanitized logging of Llama Stack configuration in query and streaming_query endpoints by copying the configuration, masking the api_key value, and logging the sanitized copy. No functional or control-flow changes; only log output is adjusted. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
Tip 🔌 Remote MCP (Model Context Protocol) integration is now available!Pro plan users can now connect to remote MCP servers from the Integrations page. Connect with popular remote MCPs such as Notion and Linear to add more context to your reviews and chats. ✨ Finishing Touches
🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (2)
src/app/endpoints/query.py (1)
177-181: Log a sanitized Llama Stack configuration at DEBUG levelThe property
llama_stack_configurationis correctly accessed without(). To avoid mutating the copy and exposing sensitive fields at INFO level, dump a sanitized dictionary and lower the log level:• File src/app/endpoints/query.py (lines 177–181):
- Replace the current copy-and-mask approach with a JSON dump excluding
api_key.- Change
logger.info→logger.debug.- Fix the typo “LLama” → “Llama”.
Suggested diff:
- # log Llama Stack configuration, but without sensitive information - llama_stack_config = configuration.llama_stack_configuration.model_copy() - llama_stack_config.api_key = "********" - logger.info("LLama stack config: %s", llama_stack_config) + # log Llama Stack configuration (sanitized) at DEBUG level + llama_stack_config = configuration.llama_stack_configuration.model_copy() + sanitized = llama_stack_config.model_dump(mode="json", exclude={"api_key"}) + logger.debug("Llama stack config: %s", sanitized)src/app/endpoints/streaming_query.py (1)
544-548: Same here: ensure callable usage, redact via dump, and use DEBUG
- Use
llama_stack_configuration()if it’s a method.- Log a sanitized dict (exclude secrets) rather than mutating the copy.
- Use DEBUG and fix casing.
Same verification script as noted in query.py to confirm property vs method.
- # log Llama Stack configuration, but without sensitive information - llama_stack_config = configuration.llama_stack_configuration.model_copy() - llama_stack_config.api_key = "********" - logger.info("LLama stack config: %s", llama_stack_config) + # log Llama Stack configuration, but without sensitive information + llama_stack_config = configuration.llama_stack_configuration().model_copy() + sanitized = llama_stack_config.model_dump(mode="json", exclude={"api_key"}) + logger.debug("Llama stack config: %s", sanitized)
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
💡 Knowledge Base configuration:
- MCP integration is disabled by default for public repositories
- Jira integration is disabled by default for public repositories
- Linear integration is disabled by default for public repositories
You can enable these sources in your CodeRabbit configuration.
📒 Files selected for processing (2)
src/app/endpoints/query.py(1 hunks)src/app/endpoints/streaming_query.py(1 hunks)
🧰 Additional context used
🧬 Code graph analysis (2)
src/app/endpoints/streaming_query.py (1)
src/configuration.py (2)
configuration(56-61)llama_stack_configuration(72-77)
src/app/endpoints/query.py (1)
src/configuration.py (2)
configuration(56-61)llama_stack_configuration(72-77)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: build-pr
- GitHub Check: e2e_tests
Description
LCORE-503: Don't log sensitive info
Type of change
Related Tickets & Documents
Summary by CodeRabbit