Skip to content

Commit 4b761f1

Browse files
MovieStoreGuyjriguera
authored andcommitted
Fix: Ensure publisher does not include token in exported data (open-telemetry#35154)
**Description:** This will ensure that tokens are not leaked through the event API. **Link to tracking Issue:** **Testing:** Updated the tests to ensure that the token isn't include in the final data.
1 parent 098c6dd commit 4b761f1

File tree

3 files changed

+30
-0
lines changed

3 files changed

+30
-0
lines changed

.chloggen/msg_fix-token-removal.yaml

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
# Use this changelog template to create an entry for release notes.
2+
3+
# One of 'breaking', 'deprecation', 'new_component', 'enhancement', 'bug_fix'
4+
change_type: bug_fix
5+
6+
# The name of the component, or a single word describing the area of concern, (e.g. filelogreceiver)
7+
component: signalfxexporter
8+
9+
# A brief description of the change. Surround your text with quotes ("") if it needs to start with a backtick (`).
10+
note: Ensure token is not sent through for event data
11+
12+
# Mandatory: One or more tracking issues related to the change. You can use the PR number here if no issue exists.
13+
issues: [35154]
14+
15+
# (Optional) One or more lines of additional information to render under the primary note.
16+
# These lines will be padded with 2 spaces and then inserted directly into the document.
17+
# Use pipe (|) for multiline entries.
18+
subtext:
19+
20+
# If your change doesn't affect end users or the exported elements of any package,
21+
# you should instead start your pull request title with [chore] or use the "Skip Changelog" label.
22+
# Optional: The change log or logs in which this entry should be included.
23+
# e.g. '[user]' or '[user, api]'
24+
# Include 'user' if the change is relevant to end users.
25+
# Include 'api' if there is a change to a library API.
26+
# Default: '[user]'
27+
change_logs: [user]

exporter/signalfxexporter/internal/translation/logdata_to_signalfxv2.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,8 @@ func convertLogRecord(lr plog.LogRecord, resourceAttrs pcommon.Map, logger *zap.
8484
return true
8585
case splunk.SFxEventPropertiesKey:
8686
return true
87+
case splunk.SFxAccessTokenLabel:
88+
return true
8789
case splunk.SFxEventType:
8890
if v.Type() == pcommon.ValueTypeStr {
8991
event.EventType = v.Str()

exporter/signalfxexporter/internal/translation/logdata_to_signalfxv2_test.go

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@ func TestLogDataToSignalFxEvents(t *testing.T) {
4848
resourceLog.Resource().Attributes().PutStr("k0", "should use ILL attr value instead")
4949
resourceLog.Resource().Attributes().PutStr("k3", "v3")
5050
resourceLog.Resource().Attributes().PutInt("k4", 123)
51+
resourceLog.Resource().Attributes().PutStr("com.splunk.signalfx.access_token", "hunter2")
5152

5253
ilLogs := resourceLog.ScopeLogs()
5354
logSlice := ilLogs.AppendEmpty().LogRecords()

0 commit comments

Comments
 (0)