mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-05 19:08:23 +00:00
Stop logging decrypted NIP-46 request/response bodies
EventNotificationConsumer persisted the decrypted bunker request
("Decrypted request: $requestStr") to the log DB, and
BunkerRequestUtils logged the full bunker response — whose result is
the plaintext for a decrypt operation. Both left cleartext at rest in
log_db_$npub (the encrypted event itself is already logged separately).
Log only non-sensitive metadata instead: the request id + method, and
the response id + error status. The encrypted event remains logged, so
diagnostics are preserved without storing plaintext.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WABMihCLr9XN51uLWj93oX
This commit is contained in:
@@ -105,13 +105,16 @@ object BunkerRequestUtils {
|
||||
}
|
||||
|
||||
Amber.instance.applicationIOScope.launch {
|
||||
// Never persist the response result — for a decrypt request it is the
|
||||
// plaintext. Record only non-sensitive metadata (id + error status).
|
||||
val sanitizedResponse = "id=${bunkerResponse.id} ${bunkerResponse.error?.let { "error=$it" } ?: "ok"}"
|
||||
relays.forEach { relay ->
|
||||
Amber.instance.getLogDatabase(account.npub).dao().insertLog(
|
||||
LogEntity(
|
||||
id = 0,
|
||||
url = relay.url,
|
||||
type = "bunker response",
|
||||
message = JacksonMapper.mapper.writeValueAsString(bunkerResponse),
|
||||
message = sanitizedResponse,
|
||||
time = System.currentTimeMillis(),
|
||||
),
|
||||
)
|
||||
|
||||
@@ -219,10 +219,13 @@ class EventNotificationConsumer(private val applicationContext: Context) {
|
||||
if (notification != null) return
|
||||
Amber.instance.notificationCache.put(event.id, event.createdAt)
|
||||
|
||||
saveLog("Decrypted request: $requestStr", relay.url, acc.npub)
|
||||
|
||||
val bunkerRequest = JacksonMapper.mapper.readValue(requestStr, BunkerRequest::class.java)
|
||||
|
||||
// Never persist the decrypted request body — it can contain plaintext
|
||||
// (e.g. the message to encrypt, or the event to sign). The encrypted event
|
||||
// is already logged above; here we record only non-sensitive metadata.
|
||||
saveLog("Decrypted request ${bunkerRequest.id} method ${bunkerRequest.method}", relay.url, acc.npub)
|
||||
|
||||
val signedEvent = if (bunkerRequest is BunkerRequestSign) {
|
||||
acc.sign(bunkerRequest.event)
|
||||
} else {
|
||||
|
||||
Reference in New Issue
Block a user