Merge pull request #16 from roseteromeo56/alert-autofix-7

Potential fix for code scanning alert no. 7: Clear-text logging of sensitive information
This commit is contained in:
Romeo Rosete 2025-05-20 10:48:02 -04:00 committed by GitHub
commit 48cebc7721
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -31,6 +31,12 @@ import (
"github.com/ethereum/go-ethereum/log" "github.com/ethereum/go-ethereum/log"
) )
// sanitizeMessage redacts sensitive information from the input string.
func sanitizeMessage(message string) string {
// Example: Replace occurrences of "password: <value>" with "password: [REDACTED]"
return strings.ReplaceAll(message, "password:", "password: [REDACTED]")
}
type CommandlineUI struct { type CommandlineUI struct {
in *bufio.Reader in *bufio.Reader
mu sync.Mutex mu sync.Mutex
@ -237,7 +243,8 @@ func (ui *CommandlineUI) ShowError(message string) {
// ShowInfo displays info message to user // ShowInfo displays info message to user
func (ui *CommandlineUI) ShowInfo(message string) { func (ui *CommandlineUI) ShowInfo(message string) {
fmt.Printf("## Info \n%s\n", message) sanitizedMessage := sanitizeMessage(message)
fmt.Printf("## Info \n%s\n", sanitizedMessage)
} }
func (ui *CommandlineUI) OnApprovedTx(tx ethapi.SignTransactionResult) { func (ui *CommandlineUI) OnApprovedTx(tx ethapi.SignTransactionResult) {