Repository navigation
fix(mqtt): mask the broker password in native error lines - #291
Merged
lxsaah merged 1 commit intoOct 5, 2026
Merged
Conversation
The native event loop logged the broker URL verbatim on every connection error, password included, and a URL missing its scheme came back in the build error the same way. Both now mask the password as ConnectorUrl's Display does: mqtt://user:****@host:port. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found during the stage 12 live run (#290). The native (
rumqttc) backend logged the broker URL verbatim whenever its event loop hit a connection error, including any password in the URL's authority:That line repeats every 5 s while the broker refuses the client. The problem predates design 054. It lands on the feature branch rather than
main, because stage 11 rewrote this code.Change (
native.rs)redacted(url): masks the password in the URL's authority the wayConnectorUrl'sDisplayalready does (mqtt://user:****@host:port). The username, host, port and path stay readable.redacted(broker_url)instead ofbroker_url.to_string().ConnectorUrl::parse's only error ("missing scheme") quotes its input, so a mistyped broker URL such asuser:s3cret@host:1884came back in the build errorInvalid MQTT URL: …, which applications are likely to log. That message now passes throughredactedtoo. A URL without://is masked the same way.Tests
redacted_masks_only_the_password: a password containing@and:, a URL with a path, a URL without a scheme, and URLs with nothing to mask (no userinfo, username only, not a URL at all).an_invalid_url_error_does_not_repeat_the_password: the build error foruser:s3cret@localhost:1884doesn't contain the password. Without the masking, the test fails (… Missing scheme in URL: user:s3cret@localhost:1884/dummy); I checked by removing it.Verification
cargo test -p aimdb-mqtt-connector --features std: 48 passed.std,std,tokio-rustlsandstd,tokio-native-tls(--all-targets -D warnings) andcargo fmt --all --check: clean.feat/054-connector-boundary.The changelog entry follows with the rest of 054 in stage 17.
🤖 Generated with Claude Code