Potential fix for code scanning alert no. 6: Clear-text logging of sensitive information

Romeo Rosete

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
Romeo Rosete 2025-05-20 11:31:03 -04:00 committed by GitHub
parent 6768ef8738
commit 75d31572bb
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -1086,9 +1086,21 @@ func GenDoc(ctx *cli.Context) error {
output []string
add = func(name, desc string, v interface{}) {
// Sanitize sensitive fields before logging
if req, ok := v.(*core.UserInputRequest); ok && req.IsPassword {
switch req := v.(type) {
case *core.UserInputRequest:
if req.IsPassword {
req.IsPassword = false // Obfuscate sensitive metadata
}
case *core.SignDataRequest:
req.Rawdata = nil // Remove raw data to avoid logging sensitive information
for i := range req.Messages {
req.Messages[i].Value = "[REDACTED]" // Obfuscate message content
}
case *core.ListRequest:
for i := range req.Accounts {
req.Accounts[i].URL.Path = "[REDACTED]" // Obfuscate account paths
}
}
if data, err := json.MarshalIndent(v, "", " "); err == nil {
output = append(output, fmt.Sprintf("### %s\n\n%s\n\nExample:\n```json\n%s\n```", name, desc, data))
} else {