Skip to content

fix(mqtt): mask the broker password in native error lines - #291

Merged
lxsaah merged 1 commit into
feat/054-connector-boundaryfrom
fix/054-redact-broker-credentials
Oct 5, 2026
Merged

lxsaah merged 1 commit into
feat/054-connector-boundaryfrom
fix/054-redact-broker-credentials

Conversation

@lxsaah

@lxsaah lxsaah commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Found during the stage 12 live run (#290). The native (rumqttc) backend logged the broker URL verbatim whenever its event loop hit a connection error, including any password in the URL's authority:

MQTT event loop error for mqtt://aimdb:nope@localhost:1884: ConnectionRefused(NotAuthorized)

That line repeats every 5 s while the broker refuses the client. The problem predates design 054. It lands on the feature branch rather than main, because stage 11 rewrote this code.

Change (native.rs)

  • New redacted(url): masks the password in the URL's authority the way ConnectorUrl's Display already does (mqtt://user:****@host:port). The username, host, port and path stay readable.
  • The event loop's log key is redacted(broker_url) instead of broker_url.to_string().
  • A second, narrower leak: ConnectorUrl::parse's only error ("missing scheme") quotes its input, so a mistyped broker URL such as user:s3cret@host:1884 came back in the build error Invalid MQTT URL: …, which applications are likely to log. That message now passes through redacted too. A URL without :// is masked the same way.
  • The embedded backend wasn't affected: its URL errors are fixed strings, and it never logs the URL.

Tests

  • redacted_masks_only_the_password: a password containing @ and :, a URL with a path, a URL without a scheme, and URLs with nothing to mask (no userinfo, username only, not a URL at all).
  • an_invalid_url_error_does_not_repeat_the_password: the build error for user:s3cret@localhost:1884 doesn't contain the password. Without the masking, the test fails (… Missing scheme in URL: user:s3cret@localhost:1884/dummy); I checked by removing it.

Verification

  • cargo test -p aimdb-mqtt-connector --features std: 48 passed.
  • Clippy on std, std,tokio-rustls and std,tokio-native-tls (--all-targets -D warnings) and cargo fmt --all --check: clean.
  • CI does not run on PRs into feat/054-connector-boundary.

The changelog entry follows with the rest of 054 in stage 17.

🤖 Generated with Claude Code

The native event loop logged the broker URL verbatim on every connection
error, password included, and a URL missing its scheme came back in the
build error the same way. Both now mask the password as ConnectorUrl's
Display does: mqtt://user:****@host:port.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@lxsaah
lxsaah merged commit bd68be1 into feat/054-connector-boundary Oct 5, 2026
@lxsaah
lxsaah deleted the fix/054-redact-broker-credentials branch October 5, 2026 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant