Skip to content

Conversation

@blgm
Copy link
Member

@blgm blgm commented Jun 6, 2025

Technically this means logging a credential, but...

  • It's a credential that's not functional
  • It's a credential for an ephemeral database with nothing of value in it
  • It's only visible to a user who can run cf logs and in practice all the users who can do that can run cf ssh and see the credential in /proc/*/environ (in principle you can have different permissions for this, but in practice this is not done on test environments)
  • So failure to log the URI just makes debugging harder - it's not adding any real security

@blgm blgm marked this pull request as draft June 6, 2025 12:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant