From 34172a7beb177b397777d60542cb60e7ea0716fe Mon Sep 17 00:00:00 2001 From: Jarred Stelfox Date: Wed, 30 Sep 2026 09:50:35 -0700 Subject: [PATCH] Stop printing GitHub secrets to the server log Every time the server or one of the bin/refresh-* scripts started, lib/git-manager.js printed the whole config.github object to stdout. That object holds the OAuth app secret, the API token and the webhook secret. In Docker, stdout goes to the container log, so anyone who can read that log can read all three. The line came in with 5db15a2 (lib: Convert to ESM) and reached master with #419 on 2025-03-04. Nothing depends on that output; it looks like a debugging print that stayed in. The webhook handler also printed the secret a caller sent whenever it didn't match hook_secret. That value can be a real secret as well, such as one meant for another Pulldasher instance, or the old one after a rotation. The handler still logs "Invalid Hook Secret", now without the value. Checked by loading both files with test/fixtures/config.js and counting the fixture's secrets in stdout and stderr. Before this change the token, the OAuth secret and the webhook secret each printed once, and a webhook call with a wrong secret printed that value twice. After it, all four counts are zero. Note: this stops new copies. It doesn't remove what earlier starts already wrote to existing logs. Co-Authored-By: Claude Opus 5.5 --- controllers/githubHooks.js | 2 +- lib/git-manager.js | 2 -- 2 files changed, 1 insertion(+), 3 deletions(-) diff --git a/controllers/githubHooks.js b/controllers/githubHooks.js index a4aee605..9b16a526 100644 --- a/controllers/githubHooks.js +++ b/controllers/githubHooks.js @@ -25,7 +25,7 @@ const HooksController = { var secret = req.query.secret; if (secret !== config.github.hook_secret) { - var m = 'Invalid Hook Secret: ' + secret; + var m = 'Invalid Hook Secret'; hooksDebug(m); console.error(m); return res.status(401).send('Invalid POST'); diff --git a/lib/git-manager.js b/lib/git-manager.js index 722d9b11..6e482006 100644 --- a/lib/git-manager.js +++ b/lib/git-manager.js @@ -19,8 +19,6 @@ import { noopPacer } from './pacer.js'; const MyOctokit = Octokit.plugin(throttling, retry); const gitDebug = debug('pulldasher:github'); -console.log(config.github); - const github = new MyOctokit({ auth: config.github.token, // Auto-retry transient 5xx/network failures (the throttle plugin only covers