[E05-S01-T04] Secret/password never appears in logs #235

Open
opened 2026-08-27 00:17:16 +00:00 by kpcto · 0 comments
Owner

Parent story: [E05-S01] Administrator bootstrap (#72)

Intent

Ensure secret and password values never appear in any log output.

Acceptance criteria

  • Secret and password values never appear in any log output
  • Log redaction covers error, request and access logs

Explicitly out of scope

  • No universal/default password (E05-S01-T01)
  • Argon2id password hashing (E05-S01-T02)
  • Documented first-run bootstrap path (E05-S01-T03)

Test plan

  • Automated test asserts no secret value appears in captured logs

Rollback note

  • Revert the logging redaction change and redeploy

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E05-S01] Administrator bootstrap (#72) ## Intent Ensure secret and password values never appear in any log output. ## Acceptance criteria - Secret and password values never appear in any log output - Log redaction covers error, request and access logs ## Explicitly out of scope - No universal/default password (E05-S01-T01) - Argon2id password hashing (E05-S01-T02) - Documented first-run bootstrap path (E05-S01-T03) ## Test plan - Automated test asserts no secret value appears in captured logs ## Rollback note - Revert the logging redaction change and redeploy ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 1 milestone 2026-08-27 00:17:16 +00:00
kpcto added the
kind
task
status
proposed
labels 2026-08-27 00:17:16 +00:00
Sign in to join this conversation.