Skip to content

security: mask root token output by default#754

Open
lhy8888 wants to merge 1 commit intoveops:masterfrom
lhy8888:codex/sec-mask-root-token
Open

security: mask root token output by default#754
lhy8888 wants to merge 1 commit intoveops:masterfrom
lhy8888:codex/sec-mask-root-token

Conversation

@lhy8888
Copy link

@lhy8888 lhy8888 commented Mar 8, 2026

Summary

Secret initialization flow printed full root token to console logs/stdout.

Security Fix

Mask token by default and only print full token when explicit env switch is enabled.

Linked Issue

Closes #753
#753

Commit

1be0610

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[SECURITY][Medium] Root token exposed in initialization output

1 participant