aws-cdk
aws-cdk copied to clipboard
fix(custom-resources): provider framework will always log all data including confidential data
Issue # (if applicable)
Closes #30275.
Reason for this change
When using a Provider to create a custom resource, the request and response objects are logged by the provider function. There is no apparent way to prevent or redact this logging, resulting in secrets being logged if returned in the custom resource's Data object. By extension, if secret values are passed in the resource's ResourceProperties they will be logged as well.
Description of changes
Allow NoEcho
fields to mask the data response to *****
.
Description of how you validated changes
Integ test covering this and verifeid in the log stream that redacted
is included in the message.
Checklist
- [x] My code adheres to the CONTRIBUTING GUIDE and DESIGN GUIDELINES
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license