Skip to content

fix(streaming): redact NATS endpoint credentials in logs - #11291

Merged
ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-streaming-redact-nats-credentials
Sep 17, 2026
Merged

ReubenBond merged 1 commit into
dotnet:mainfrom
ReubenBond:rb-fix-streaming-redact-nats-credentials

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Problem

The NATS connection manager writes configured server URLs directly into connection and JetStream log fields. Seed URLs can contain username/password or token credentials, exposing them in logs.

Solution

Extract the endpoint-description helper from #10798 and apply it at all five existing endpoint logging call sites. Each comma-separated seed endpoint has its URI username and password removed, while its address remains available for diagnostics. Connection options retain their original URLs for authentication.

Focused offline regression tests assert exact descriptions for username/password and token credentials, multiple seed endpoints, encoded credentials, endpoint normalization, and invalid endpoint placeholders.

Rationale

This isolates the existing logging fix as a small prerequisite to the Aspire integration: one runtime source file and one focused test file. The original implementation is from commit 61eefc2 by Reuben Bond reuben.bond@gmail.com; the extraction preserves that authorship and records the source commit.

#10798 retains the helper and its shared-connection use until this prerequisite is human-merged.

Microsoft Reviewers: Open in CodeFlow

Remove URI usernames and passwords from every configured NATS seed endpoint before writing connection and JetStream log fields. Preserve the configured client URLs for authentication and retain endpoint addresses for diagnostics.

Extracted from dotnet#10798. Original implementation: 61eefc2 (Reuben Bond <reuben.bond@gmail.com>). Add focused offline exact-output regressions for user/password, token, multi-seed, and invalid endpoint descriptions.
Copilot AI lite review requested due to automatic review settings September 17, 2026 02:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues remain, and focused regression tests are included.

Review effort: Lite
Findings: None

What changed in this PR

This PR prevents NATS endpoint credentials from appearing in logs while preserving original URLs for authentication.

Changes:

  • Adds credential-safe endpoint descriptions at all logging call sites.
  • Adds regression tests for redaction, normalization, and invalid endpoints.
File Description
test/​Extensions/​Orleans.Streaming.NATS.Tests/​NatsConnectionManagerTests.cs Tests credential redaction and endpoint handling.
src/​Orleans.Streaming.NATS/​Providers/​NatsConnectionManager.cs Redacts credentials before endpoint logging.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
@github-actions

Copy link
Copy Markdown
Contributor

Code coverage

Metric Pull request Current main Variance
Lines 82.12% (112,280 / 136,728) 82.12% (112,272 / 136,709) -0.0056 pp
Branches 71.29% (32,293 / 45,299) 71.32% (32,306 / 45,295) -0.0350 pp

Report-only conclusion: regressed.

The current-main baseline is commit 2e40fa8a3b and uses the same reviewed coverage matrix.

Coverage combines every CI test matrix job, including providers, CodeGen, .NET 8/10, Linux, Windows, and macOS, using canonical physical source and branch identities.

The comparison remains report-only while normal line and branch variance is calibrated.

Coverage details

@ReubenBond
ReubenBond merged commit ab16bba into dotnet:main Sep 17, 2026
73 checks passed
@ReubenBond
ReubenBond deleted the rb-fix-streaming-redact-nats-credentials branch September 17, 2026 14:11
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
ReubenBond added a commit to ReubenBond/orleans that referenced this pull request Sep 17, 2026
Move independent NATS producer selection and dimension validation to dotnet#11287 and dotnet#11293. Move standalone redaction, credential, and journaling regression coverage to dotnet#11288, dotnet#11289, dotnet#11291, and dotnet#11292; move the independent DynamoDB README recipes to dotnet#11292.

Retain Token redaction, credential binding and endpoint behavior, journaling activation, and NATS credential-safe logging as prerequisites until dotnet#11288, dotnet#11290, dotnet#11292, dotnet#11289, and dotnet#11291 are merged by humans. The original PR remains focused on Aspire configuration, resource ownership, and integration coverage.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants