Potential fix for code scanning alert no. 7: Clear-text logging of sensitive information

Romeo Rosete

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
Romeo Rosete 2025-05-20 10:43:33 -04:00 committed by GitHub
parent f40cd2cdf8
commit 752236dbfe
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -31,6 +31,12 @@ import (
"github.com/ethereum/go-ethereum/log" "github.com/ethereum/go-ethereum/log"
) )
// sanitizeMessage redacts sensitive information from the input string.
func sanitizeMessage(message string) string {
// Example: Replace occurrences of "password: <value>" with "password: [REDACTED]"
return strings.ReplaceAll(message, "password:", "password: [REDACTED]")
}
type CommandlineUI struct { type CommandlineUI struct {
in *bufio.Reader in *bufio.Reader
mu sync.Mutex mu sync.Mutex
@ -237,7 +243,8 @@ func (ui *CommandlineUI) ShowError(message string) {
// ShowInfo displays info message to user // ShowInfo displays info message to user
func (ui *CommandlineUI) ShowInfo(message string) { func (ui *CommandlineUI) ShowInfo(message string) {
fmt.Printf("## Info \n%s\n", message) sanitizedMessage := sanitizeMessage(message)
fmt.Printf("## Info \n%s\n", sanitizedMessage)
} }
func (ui *CommandlineUI) OnApprovedTx(tx ethapi.SignTransactionResult) { func (ui *CommandlineUI) OnApprovedTx(tx ethapi.SignTransactionResult) {