Skip to content

fix: remove Infisical access token from error message - #5

Open
whoiskatrin wants to merge 1 commit into
Infisical:mainfrom
whoiskatrin:fix/hide-infisical-token
Open

fix: remove Infisical access token from error message#5
whoiskatrin wants to merge 1 commit into
Infisical:mainfrom
whoiskatrin:fix/hide-infisical-token

Conversation

@whoiskatrin

Copy link
Copy Markdown

access token was being included in the returned error msg, which is a security risk

✅ Changes

  • Removed accessToken from the error message in src/index.ts.
  • Error now only includes the message itself

How to test this

  1. Force an error in listProjects (e.g. invalid token or network issue).
  2. Confirm that the returned message does not contain the access token.

@infisical-cla-app

Copy link
Copy Markdown

📝 Contributor License Agreement required

Before this PR can merge, every contributor must sign the Infisical CLA.
Signing is quick: sign in with GitHub, review the CLA, and accept.

👉 Sign the CLA

Still needs to sign:

Once everyone has signed, the check updates automatically — no need to close and reopen the PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant