boulder icon indicating copy to clipboard operation
boulder copied to clipboard

va: restrict logging of too-long redirect targets

Open jsha opened this issue 3 years ago • 1 comments

Right now the va rejects too-long redirect targets, but will log the whole thing. We should truncate the logged URL to our max size, so we don't make our logs too big.

jsha avatar May 24 '22 22:05 jsha

This just came up again, but this time the too-long hostname got logged not simply because it was too long, but also because it didn't end in an IANA TLD. This is actually why we haven't tackled this bug yet: there are a bunch of places where the VA logs the hostname it's trying to validate, and truncating all of them is non-trivial.

aarongable avatar Jan 05 '24 00:01 aarongable