Skip to content

Says what still carries the token at :debug - #180

Merged
johnnyt merged 1 commit into
mainfrom
se-2poc-holddesk-token-log-wording
Oct 2, 2026
Merged

johnnyt merged 1 commit into
mainfrom
se-2poc-holddesk-token-log-wording

Conversation

@johnnyt

@johnnyt johnnyt commented Oct 2, 2026

Copy link
Copy Markdown
Member

What

Docs and comments only; no config value and no code path changes.

  • StatifierExamples.HoldDesk moduledoc: a new "The :debug limit" paragraph. statifier_router 0.10.0 runs its own token statements with Ecto's log: false; the token still reaches a :debug repo through the position writes (printed with the blob cut short by Ecto's inspect limit) and through Ecto's query telemetry event, which carries the bound parameters of the position writes and of the desk post job's insert. The bearer paragraph now says where the location is stored and that whoever can read those tables holds the capability.
  • StatifierExamplesWeb.BasicHTTPController moduledoc: the stale reason (the router's lookup binds the token) is replaced with what 0.10.0 does and a pointer to the hold desk's moduledoc.
  • config/config.exs: the :filter_parameters comment says the filter matches any param whose key contains "token", so it also redacts the CSRF token.
  • docs/guides/basichttp-front.md: the bearer-capability section names the three places the location is stored (the router's location table, the execution's position_blob in the clear, the desk post job's arguments) and gives the current reason for keeping :debug out of production; the job-row sentence says this app configures no Oban pruner and links back to the bearer section.

Verified

  • Oban 2.24.1 (mix.lock) starts a pruner only when the :pruner key is given (Oban.Config's service plugins); config/config.exs gives none.
  • Oban runs its own statements with log: conf.log, false by default (Oban.Repo.default_options/1); this app sets no :log. A throwaway test (not committed) inserted a desk post job inside a repo transaction at :debug: the query log printed only begin and commit, and the repo's query telemetry event for the oban_jobs insert carried the job's arguments.
  • Ecto.Adapters.SQL's private log/5 emits the query telemetry event before it reads the log option.
  • Phoenix.Logger.filter_values/2 discards a value whose key contains a listed string.
  • StatifierExamples.Persistence passes blob_type: :binary; statifier_persistence's statements set no log: false.
  • The router's half is statifier_router's docs/adr/0002-addressing.md, the Note of 2026-10-02 on the location token and the query log, at v0.10.0.

Provenance

The bead's second fold-item expected the job insert's arguments to appear in Ecto's :debug query log. They do not (Oban suppresses its own query log lines); they appear in the query telemetry event, and the text says that instead.

Review

Tier: gate (docs and moduledocs). Own review round on the branch before opening; no record text is changed. mix quality green on the committed tree.

statifier_router 0.10.0 keeps the location token out of its own query
log, so the hold desk's moduledoc, the controller's moduledoc and the
guide no longer give the router's binds as the reason to keep :debug
out of production. They name what remains: the position writes, which
Ecto prints with the blob cut short, and the query telemetry event,
which carries the position writes and the desk post job's insert. Oban
runs its own statements with log: false, so the job insert prints no
query log line.

The guide and the moduledoc also say where the location is stored -
the router's location table, the execution's position_blob in the
clear, and the desk post job's arguments - and that whoever can read
those tables holds the capability. This app configures no Oban pruner
and Oban prunes nothing by default, so the job rows stay.

The filter_parameters comment says that "token" also redacts any other
param whose key contains it, the CSRF token among them. No config
value changes.

Refs: se-2poc
@johnnyt
johnnyt merged commit e93f4be into main Oct 2, 2026
3 checks passed
@johnnyt
johnnyt deleted the se-2poc-holddesk-token-log-wording branch October 2, 2026 12:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant