Merge pull request #21 from roseteromeo56/alert-autofix-6

Potential fix for code scanning alert no. 6: Clear-text logging of sensitive information
This commit is contained in:
Romeo Rosete 2025-05-20 11:25:06 -04:00 committed by GitHub
commit 4c49018214
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1085,6 +1085,10 @@ func GenDoc(ctx *cli.Context) error {
} }
output []string output []string
add = func(name, desc string, v interface{}) { add = func(name, desc string, v interface{}) {
// Sanitize sensitive fields before logging
if req, ok := v.(*core.UserInputRequest); ok && req.IsPassword {
req.IsPassword = false // Obfuscate sensitive metadata
}
if data, err := json.MarshalIndent(v, "", " "); err == nil { if data, err := json.MarshalIndent(v, "", " "); err == nil {
output = append(output, fmt.Sprintf("### %s\n\n%s\n\nExample:\n```json\n%s\n```", name, desc, data)) output = append(output, fmt.Sprintf("### %s\n\n%s\n\nExample:\n```json\n%s\n```", name, desc, data))
} else { } else {