akka-tracing icon indicating copy to clipboard operation
akka-tracing copied to clipboard

Play!: Expose application filter to exclude fields in trace

Open drpacman opened this issue 9 years ago • 0 comments

At present all query parameters and headers are added to the trace. This introduces a security risk if some of those fields contain sensitive information e.g. authentication tokens etc.

To mitigate this, enable query fields or header fields to be excluded from the trace (or at least masked with a dummy value) by the hosting application.

I think this will be simple to achieve by adding configurable filters to akka.tracing.play.TracingSettings which can be applied in addHttpAnnotations.

(I will try and implement this week)

drpacman avatar Jul 06 '15 08:07 drpacman