Our configuration mechanism currently logs all the configured values.
This makes it hard to use it for passwords and stuff.
I suggest we introduce some specific prefix property to configure configs which contain sensitive information.
For the key 'some.random.password' this could look like:
In the log we would in this case just output the information whether and where we did find some value, but not print the details for all configs which start with all of the configured masks.
I'm not yet sure though how to configure this best. Suggestions appreciated!
|Transition||Time In Source Status||Execution Times||Last Executer||Last Execution Date|
|19d 14h 42m||1||Mark Struberg||03/Jul/13 05:13|
|260d 2h 31m||1||Gerhard Petracek||20/Mar/14 07:44|
|Status||Resolved [ 5 ]||Closed [ 6 ]|
|Status||Open [ 1 ]||Resolved [ 5 ]|
|Resolution||Fixed [ 1 ]|
|Field||Original Value||New Value|
|Summary||mask out passwords and other credentials||mask out passwords and other credentials in our Configuration logs|