Avoid logging sensitive data
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
ID: javascript-node-security/log-sensitive-data
Language: JavaScript
Severity: Warning
Category: Security
CWE: 532
Description
Do not log sensitive data such as user id, email or other personal data (first name, last name, etc).
Non-Compliant Code Examples
console.log("email from user" + user.email);
console.log(`email from user ${user.email}`);
logger.info(`email from user ${user.email}`);
logger.info(`email from user ${user.name}: ${user.email}`);
logger.info(`email from user ${username}: ${user.email}`);
logger.warn(email);
logger.error(`email from user ${email}`);
foobar.error(`email from user ${email}`);
logger.foobar(`email from user ${email}`);
Compliant Code Examples
console.log("email from user" + user.id);
console.log(`email from user ${user.uuid}`);