Stop logging decrypted NIP-46 request/response bodies

EventNotificationConsumer persisted the decrypted bunker request
("Decrypted request: $requestStr") to the log DB, and
BunkerRequestUtils logged the full bunker response — whose result is
the plaintext for a decrypt operation. Both left cleartext at rest in
log_db_$npub (the encrypted event itself is already logged separately).

Log only non-sensitive metadata instead: the request id + method, and
the response id + error status. The encrypted event remains logged, so
diagnostics are preserved without storing plaintext.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WABMihCLr9XN51uLWj93oX
This commit is contained in:
Claude
2026-06-19 10:40:15 +00:00
parent c37f5291e8
commit d03dfd8236
2 changed files with 9 additions and 3 deletions
@@ -105,13 +105,16 @@ object BunkerRequestUtils {
}
Amber.instance.applicationIOScope.launch {
// Never persist the response result — for a decrypt request it is the
// plaintext. Record only non-sensitive metadata (id + error status).
val sanitizedResponse = "id=${bunkerResponse.id} ${bunkerResponse.error?.let { "error=$it" } ?: "ok"}"
relays.forEach { relay ->
Amber.instance.getLogDatabase(account.npub).dao().insertLog(
LogEntity(
id = 0,
url = relay.url,
type = "bunker response",
message = JacksonMapper.mapper.writeValueAsString(bunkerResponse),
message = sanitizedResponse,
time = System.currentTimeMillis(),
),
)
@@ -219,10 +219,13 @@ class EventNotificationConsumer(private val applicationContext: Context) {
if (notification != null) return
Amber.instance.notificationCache.put(event.id, event.createdAt)
saveLog("Decrypted request: $requestStr", relay.url, acc.npub)
val bunkerRequest = JacksonMapper.mapper.readValue(requestStr, BunkerRequest::class.java)
// Never persist the decrypted request body — it can contain plaintext
// (e.g. the message to encrypt, or the event to sign). The encrypted event
// is already logged above; here we record only non-sensitive metadata.
saveLog("Decrypted request ${bunkerRequest.id} method ${bunkerRequest.method}", relay.url, acc.npub)
val signedEvent = if (bunkerRequest is BunkerRequestSign) {
acc.sign(bunkerRequest.event)
} else {