fix(aws): redact DynamoDB tokens - #11288
Conversation
Redact session tokens in shared DynamoDB client options and cover real options logging across clustering, gateway, persistence, reminders, and transactions. Regenerate all four affected public API surfaces. Extracted-from: dotnet#10798 Original-commit: d2db3d6 Rebased-commit: c5eae99
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified, and coverage validates token redaction across the affected providers.
Review effort: Lite
Findings: None
What changed in this PR
Updates DynamoDB client option logging to redact session tokens and adds regression coverage across AWS providers.
Changes:
- Applies
[Redact]toDynamoDBClientOptions.Token. - Adds options-logging tests for all DynamoDB provider variants.
- Regenerates four affected API surfaces.
- Adds the transactions provider test reference.
| File | Description |
|---|---|
test/Extensions/Orleans.AWS.Tests/Orleans.AWS.Tests.csproj |
References the transactions DynamoDB project. |
test/Extensions/Orleans.AWS.Tests/DynamoDBOptionsLoggingTests.cs |
Verifies credential redaction and safe diagnostic fields. |
src/AWS/Shared/Storage/DynamoDBClientOptions.cs |
Redacts DynamoDB session tokens. |
src/api/AWS/Orleans.Transactions.DynamoDB/Orleans.Transactions.DynamoDB.cs |
Regenerated transactions API surface. |
src/api/AWS/Orleans.Reminders.DynamoDB/Orleans.Reminders.DynamoDB.cs |
Regenerated reminders API surface. |
src/api/AWS/Orleans.Persistence.DynamoDB/Orleans.Persistence.DynamoDB.cs |
Regenerated persistence API surface. |
src/api/AWS/Orleans.Clustering.DynamoDB/Orleans.Clustering.DynamoDB.cs |
Regenerated clustering API surface. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Code coverage
Report-only conclusion: current-main baseline stale. The newest successful coverage run tested 68f1f47, not current main 2e40fa8. Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities. The comparison remains report-only while normal line and branch variance is calibrated. Coverage details |
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292. Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
DynamoDB client options redact access and secret keys, but currently write session tokens in plaintext when Orleans formats options for logging.
Add
[Redact]toDynamoDBClientOptions.Token, which is shared by clustering, persistence, reminders, and transactions. Session tokens now receive the same redaction as the other credentials, while service and profile information remain available for diagnostics.Add focused regression coverage through the real
OptionsLoggerand registered default/namedIOptionFormatterimplementations for all four provider assemblies, including gateway options. Regenerate the four affected API surfaces; each generated change adds only the Token attribute.Extracted from #10798 so the credential-redaction fix can ship independently. Original implementation by Reuben Bond in
d2db3d6eae264fa7f13c15922a36ab359761428b(rebased asc5eae99187c1a4216c7adcb034ff12af9c00eea8).Microsoft Reviewers: Open in CodeFlow