boulder
boulder copied to clipboard
va: restrict logging of too-long redirect targets
Right now the va rejects too-long redirect targets, but will log the whole thing. We should truncate the logged URL to our max size, so we don't make our logs too big.
This just came up again, but this time the too-long hostname got logged not simply because it was too long, but also because it didn't end in an IANA TLD. This is actually why we haven't tackled this bug yet: there are a bunch of places where the VA logs the hostname it's trying to validate, and truncating all of them is non-trivial.