Skip to content

Commit

Permalink
fix(custom-resources): provider framework will always log all data in…
Browse files Browse the repository at this point in the history
…cluding confidential data (#30689)

### Issue # (if applicable)

Closes #30275.

### Reason for this change

When using a Provider to create a custom resource, the request and response objects are logged by the provider function. There is no apparent way to prevent or redact this logging, resulting in secrets being logged if returned in the custom resource's Data object. By extension, if secret values are passed in the resource's ResourceProperties they will be logged as well.

### Description of changes

Allow `NoEcho` fields to mask the data response to `*****`.

### Description of how you validated changes

Integ test covering this and verifeid in the log stream that `redacted` is included in the message.

### Checklist
- [x] My code adheres to the [CONTRIBUTING GUIDE](https:/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https:/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md)

----

*By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
  • Loading branch information
GavinZZ authored Jul 16, 2024
1 parent 38e2ecf commit 9bd92da
Show file tree
Hide file tree
Showing 110 changed files with 37,541 additions and 2,134 deletions.

This file was deleted.

Loading

0 comments on commit 9bd92da

Please sign in to comment.