TRUNK-6550: Logging should not be vulnerable to injection attacks#6128
Open
jwnasambu wants to merge 2 commits into
Open
TRUNK-6550: Logging should not be vulnerable to injection attacks#6128jwnasambu wants to merge 2 commits into
jwnasambu wants to merge 2 commits into
Conversation
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## master #6128 +/- ##
============================================
+ Coverage 59.04% 59.12% +0.07%
- Complexity 9237 9254 +17
============================================
Files 693 693
Lines 37257 37271 +14
Branches 5485 5487 +2
============================================
+ Hits 21999 22037 +38
+ Misses 13287 13252 -35
- Partials 1971 1982 +11 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
c1b5d35 to
8b02b2b
Compare
|
Contributor
Author
|
@dkayiwa, @chibongho kindly feel free to review my PR at your convenient time please! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description of what I changed
I updated logging statements to prevent log injection vulnerabilities by sanitizing untrusted input before writing it to logs. Specifically, carriage return (\r) and newline (\n) characters are replaced to prevent attackers from forging or manipulating log entries. This ensures log integrity and aligns with secure logging practices recommended by SonarQube and OWASP.
Issue I worked on
https://openmrs.atlassian.net/browse/TRUNK-6550
Checklist: I completed these to help reviewers :)
My IDE is configured to follow the code style of this project.
No? Unsure? -> configure your IDE, format the code and add the changes with
git add . && git commit --amendI have added tests to cover my changes. (If you refactored
existing code that was well tested you do not have to add tests)
No? -> write tests and add them to this commit
git add . && git commit --amendI ran
mvn clean packageright before creating this pull request andadded all formatting changes to my commit.
No? -> execute above command
All new and existing tests passed.
No? -> figure out why and add the fix to your commit. It is your responsibility to make sure your code works.
My pull request is based on the latest changes of the master branch.
No? Unsure? -> execute command
git pull --rebase upstream master