Merge pull request #3 from venkateshpabbati/alert-autofix-14
Potential fix for code scanning alert no. 14: Clear-text logging of sensitive information
This commit is contained in:
@@ -77,6 +77,7 @@ class TiDB:
|
|||||||
try:
|
try:
|
||||||
result = conn.execute(text(sql), params)
|
result = conn.execute(text(sql), params)
|
||||||
except Exception as e:
|
except Exception as e:
|
||||||
|
sanitized_params = sanitize_sensitive_info(params)
|
||||||
sanitized_params = sanitize_sensitive_info(params)
|
sanitized_params = sanitize_sensitive_info(params)
|
||||||
logger.error(f"Tidb database,\nsql:{sql},\nparams:{sanitized_params},\nerror:{sanitize_sensitive_info({'error': str(e)})}")
|
logger.error(f"Tidb database,\nsql:{sql},\nparams:{sanitized_params},\nerror:{sanitize_sensitive_info({'error': str(e)})}")
|
||||||
raise
|
raise
|
||||||
|
Reference in New Issue
Block a user