Skip to main content

Extend Well-Known secret masking

extend the well known secret masking to the password segment of URIs.


examples:

https://username:password@git.example.com/user/repo.git

ssh://user:password@host:port/path

postgres://username:password@host:port/database

Workaround
no
Problem
Status: 🗑️ Archived2 comments

Log in to comment and vote

Comments2

  • Black Breeze

    •

    Jun 10, 2025

    Archiving due to inactivity.

  • Black Breeze

    •

    May 7, 2025

    Thanks for flagging this—really helpful.

    Quick question back: how are these URIs ending up in logs in the first place? We’re curious what surface is leaking them.

    For example:

    • Is the password part showing up in Terraform plan output?

    • Or being echoed by a script or hook?

    • Or logged as part of a CLI command?

    Our default posture is to avoid logging sensitive data altogether—so if these values are leaking, it’s likely happening via user-defined logic (e.g. shell scripts, Terraform output, or custom tools). Understanding that path would help us know whether masking is the right fix—or whether we need to tighten the input/output surfaces upstream.

    If you can share where and how you’re seeing it, we can make sure it’s addressed the right way—not just band-aided.

    Thanks again—this is exactly the kind of sharp edge we want to blunt.