Keeps the location token out of the query log - #149
Merged
Merged
Conversation
At :debug, Ecto's query log prints every bound parameter, and three statements bind the BasicHTTP location token: the front's lookup, the location insert at create and the rotation's upsert. Each now passes log: false on the repo call itself; no other statement changes. A dated Note on ADR-0002 records that the token is part of the execution's persisted state, that this package keeps it out of its own query log only (the query telemetry event still carries the parameters), and the mitigation: rotation, and never :debug in production. Refs: sr-d2j1
johnnyt
force-pushed
the
sr-d2j1-keep-token-out-of-query-log
branch
from
October 2, 2026 09:51
ca2f85e to
9ae971e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
At the
:debuglevel Ecto's query log prints every bound parameter, andthree of this package's statements bind the BasicHTTP location token, so a
host running at
:debughad the token printed by this package's ownstatements. Ruled by the operator, 2026-10-01: those statements run with
Ecto's
log: falseoption and nothing else changes.StatifierRouter.BasicHTTP.Front, privateresolve/2: the lookup builtby
address_by_token/2now runs asconfig.repo.one(query, log: false).StatifierRouter.Delivery, privatelocate/3: the location insert atcreate now runs as
config.repo.insert!(row, log: false).StatifierRouter.BasicHTTP.rotate_location/2: the upsert gainslog: falsebeside itson_conflictandconflict_targetoptions.How: the option goes on the repo call itself, not through the
Confighelpers (
Config.put_meta/2andConfig.queryable/2only place the row andthe query in the configured table and prefix). No other statement binds the
token;
BasicHTTP.location/2binds only the execution id and is untouched.No table, option, answer or transaction changes.
The test
test/statifier_router/basic_http_query_log_test.exs, "the debug querylog": it raises the logger to
:debug(restored inon_exit; the moduleis
async: falsebecause the level is global), drives a create, a frontPOST, a rotation and a POST at the new location inside
capture_log/2, andfinds neither token in any log entry that names one of this package's
tables. The assertion is scoped to those entries because the capture also
holds statifier_persistence's execution insert and update, whose
position_blobcarries the location inside_ioprocessors(cut short byEcto's inspect limit, so unreadable there, not absent); those statements
are that package's. A positive control asserts this package's address
statements did print at
:debug.Sabotage, one mutation at a time, each restored byte-equal before the next:
dropping
log: falsefrom the lookup, from the create's insert and from theupsert each turned the test red on that statement's own log line.
The record
A dated Note at the foot of
docs/adr/0002-addressing.md(zero removedlines): the three statements; the token is part of the execution's
persisted state (written into
_ioprocessorsonce at session start, andinto
position_blobby statifier_persistence on every create and step, inthe clear unless the host passes an encrypting
:blob_type); this packagekeeps it out of its own query log only, since ecto_sql 3.14.0's
Ecto.Adapters.SQLemits the query telemetry event with the parametersbefore it reads
log; after a rotation the persisted_ioprocessorsstillnames the old token, as the location Amendment's "What rotation does not
reach" bullet already says; the mitigation is rotation and never
:debugin production. Every claim was checked against the dependency sources
locked in
mix.lock(statifier 2.10.0, statifier_persistence 0.18.0,ecto_sql 3.14.0) and this branch.
Changelog
changelog.d/sr-d2j1.md, under Security.Gate
Full
mix qualitygreen on the branch head before the push.Provenance
The branch was cut before the outbound-send Amendment merged to ADR-0002;
this Note was re-appended after that Amendment at the foot of the file
(additive, keep-both), and the full gate ran on the rebased head. The test
file is new rather than a case in
basic_http_test.exs, because thatmodule is
async: trueand this test changes the global logger level.Review tier: a cold review, dispatched separately.