Stop printing GitHub secrets to the server log - #505
Merged
Merged
Conversation
Every time the server or one of the bin/refresh-* scripts started, lib/git-manager.js printed the whole config.github object to stdout. That object holds the OAuth app secret, the API token and the webhook secret. In Docker, stdout goes to the container log, so anyone who can read that log can read all three. The line came in with 5db15a2 (lib: Convert to ESM) and reached master with #419 on 2025-03-04. Nothing depends on that output; it looks like a debugging print that stayed in. The webhook handler also printed the secret a caller sent whenever it didn't match hook_secret. That value can be a real secret as well, such as one meant for another Pulldasher instance, or the old one after a rotation. The handler still logs "Invalid Hook Secret", now without the value. Checked by loading both files with test/fixtures/config.js and counting the fixture's secrets in stdout and stderr. Before this change the token, the OAuth secret and the webhook secret each printed once, and a webhook call with a wrong secret printed that value twice. After it, all four counts are zero. Note: this stops new copies. It doesn't remove what earlier starts already wrote to existing logs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
jarstelfox
added a commit
that referenced
this pull request
Sep 30, 2026
The deployed images print GitHub secrets to their logs on every start; master stopped that, so bring it in before this branch deploys again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖
Every time Pulldasher starts, it writes three GitHub secrets into its log: the OAuth app secret, the API token and the webhook secret. Anyone who can read that log can read all three. This removes the line that prints them, and stops the webhook handler from logging the wrong secret a caller sent.
Summary
console.log(config.github)runs whenever something loadslib/git-manager.js, so the server and all sixbin/refresh-*scripts print it. It came in with 5db15a2 and has been on master since Bump @octokit/request, @octokit/plugin-throttling and @octokit/rest #419 merged on 2025-03-04.?secret=is logged with the value it sent, and that value can be a real secret, such as another instance's. It still logsInvalid Hook Secret, now without the value.Nothing else on the server logs a secret. The MySQL password only goes into the database connection, and Octokit replaces the token with
[REDACTED]in the errors we log.Output with the test config, before and after
On master, loading
lib/git-manager.jsprints:A webhook call with
?secret=wrong-valuethen addsInvalid Hook Secret: wrong-value. On this branch the first prints nothing and the second prints onlyInvalid Hook Secret.Note
Deploying this stops new copies. Logs written before the deploy still hold what was printed then.
QA
Run
npm teston Node 24. CI only runs lint and build.From the repo root, run this and confirm it prints nothing:
CONFIG_PATH=../test/fixtures/config.js node --input-type=module -e "await import('./lib/git-manager.js'); process.exit(0)"Run this and confirm it prints
Invalid Hook Secretwithoutwrong-value:CONFIG_PATH=../test/fixtures/config.js node --input-type=module -e "const { default: hooks } = await import('./controllers/githubHooks.js'); hooks.main({ query: { secret: 'wrong-value' } }, { status() { return this; }, send() {} }); process.exit(0)"🤖 Generated with Claude Code