Skip to content

fix(aws): redact DynamoDB tokens - #11288

Merged
ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-aws-redact-dynamodb-tokens-1be
Sep 17, 2026
Merged

ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-aws-redact-dynamodb-tokens-1be

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

DynamoDB client options redact access and secret keys, but currently write session tokens in plaintext when Orleans formats options for logging.

Add [Redact] to DynamoDBClientOptions.Token, which is shared by clustering, persistence, reminders, and transactions. Session tokens now receive the same redaction as the other credentials, while service and profile information remain available for diagnostics.

Add focused regression coverage through the real OptionsLogger and registered default/named IOptionFormatter implementations for all four provider assemblies, including gateway options. Regenerate the four affected API surfaces; each generated change adds only the Token attribute.

Extracted from #10798 so the credential-redaction fix can ship independently. Original implementation by Reuben Bond in d2db3d6eae264fa7f13c15922a36ab359761428b (rebased as c5eae99187c1a4216c7adcb034ff12af9c00eea8).

Microsoft Reviewers: Open in CodeFlow

Redact session tokens in shared DynamoDB client options and cover real options logging across clustering, gateway, persistence, reminders, and transactions. Regenerate all four affected public API surfaces.

Extracted-from: dotnet#10798
Original-commit: d2db3d6
Rebased-commit: c5eae99
Copilot AI lite review requested due to automatic review settings September 17, 2026 02:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified, and coverage validates token redaction across the affected providers.

Review effort: Lite
Findings: None

What changed in this PR

Updates DynamoDB client option logging to redact session tokens and adds regression coverage across AWS providers.

Changes:

  • Applies [Redact] to DynamoDBClientOptions.Token.
  • Adds options-logging tests for all DynamoDB provider variants.
  • Regenerates four affected API surfaces.
  • Adds the transactions provider test reference.
File Description
test/​Extensions/​Orleans.AWS.Tests/​Orleans.AWS.Tests.csproj References the transactions DynamoDB project.
test/​Extensions/​Orleans.AWS.Tests/​DynamoDBOptionsLoggingTests.cs Verifies credential redaction and safe diagnostic fields.
src/​AWS/​Shared/​Storage/​DynamoDBClientOptions.cs Redacts DynamoDB session tokens.
src/​api/​AWS/​Orleans.Transactions.DynamoDB/​Orleans.Transactions.DynamoDB.cs Regenerated transactions API surface.
src/​api/​AWS/​Orleans.Reminders.DynamoDB/​Orleans.Reminders.DynamoDB.cs Regenerated reminders API surface.
src/​api/​AWS/​Orleans.Persistence.DynamoDB/​Orleans.Persistence.DynamoDB.cs Regenerated persistence API surface.
src/​api/​AWS/​Orleans.Clustering.DynamoDB/​Orleans.Clustering.DynamoDB.cs Regenerated clustering API surface.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
@github-actions

Copy link
Copy Markdown
Contributor

Code coverage

Metric Pull request
Lines 82.06% (112,021 / 136,505)
Branches 71.20% (32,197 / 45,219)

Report-only conclusion: current-main baseline stale.

The newest successful coverage run tested 68f1f47, not current main 2e40fa8.

Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities.

The comparison remains report-only while normal line and branch variance is calibrated.

Coverage details

@ReubenBond
ReubenBond merged commit ab71807 into dotnet:main Sep 17, 2026
73 checks passed
@ReubenBond
ReubenBond deleted the rb-fix-aws-redact-dynamodb-tokens-1be branch September 17, 2026 14:03
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants