mirror of
https://github.com/Tencent/WeKnora.git
synced 2026-09-24 16:29:01 +08:00
refactor: Sanitize log inputs in chunk and session handlers to enhance security
This commit is contained in:
@@ -139,11 +139,7 @@ func (s *chunkService) ListChunksByKnowledgeID(ctx context.Context, knowledgeID
|
||||
func (s *chunkService) ListPagedChunksByKnowledgeID(ctx context.Context,
|
||||
knowledgeID string, page *types.Pagination, chunkType []types.ChunkType,
|
||||
) (*types.PageResult, error) {
|
||||
logger.Info(ctx, "Start listing paged chunks by knowledge ID")
|
||||
logger.Infof(ctx, "Knowledge ID: %s, page: %d, page size: %d", knowledgeID, page.Page, page.PageSize)
|
||||
|
||||
tenantID := ctx.Value(types.TenantIDContextKey).(uint64)
|
||||
logger.Infof(ctx, "Tenant ID: %d", tenantID)
|
||||
chunks, total, err := s.chunkRepository.ListPagedChunksByKnowledgeID(ctx, tenantID, knowledgeID, page, chunkType, "")
|
||||
if err != nil {
|
||||
logger.ErrorWithFields(ctx, err, map[string]interface{}{
|
||||
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
"github.com/Tencent/WeKnora/internal/logger"
|
||||
"github.com/Tencent/WeKnora/internal/types"
|
||||
"github.com/Tencent/WeKnora/internal/types/interfaces"
|
||||
secutils "github.com/Tencent/WeKnora/internal/utils"
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
@@ -193,7 +194,7 @@ func (h *Handler) GetSession(c *gin.Context) {
|
||||
logger.Info(ctx, "Start retrieving session")
|
||||
|
||||
// Get session ID from URL parameter
|
||||
id := c.Param("id")
|
||||
id := secutils.SanitizeForLog(c.Param("id"))
|
||||
if id == "" {
|
||||
logger.Error(ctx, "Session ID is empty")
|
||||
c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error()))
|
||||
@@ -257,7 +258,7 @@ func (h *Handler) UpdateSession(c *gin.Context) {
|
||||
ctx := c.Request.Context()
|
||||
|
||||
// Get session ID from URL parameter
|
||||
id := c.Param("id")
|
||||
id := secutils.SanitizeForLog(c.Param("id"))
|
||||
if id == "" {
|
||||
logger.Error(ctx, "Session ID is empty")
|
||||
c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error()))
|
||||
@@ -308,7 +309,7 @@ func (h *Handler) DeleteSession(c *gin.Context) {
|
||||
ctx := c.Request.Context()
|
||||
|
||||
// Get session ID from URL parameter
|
||||
id := c.Param("id")
|
||||
id := secutils.SanitizeForLog(c.Param("id"))
|
||||
if id == "" {
|
||||
logger.Error(ctx, "Session ID is empty")
|
||||
c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error()))
|
||||
|
||||
Reference in New Issue
Block a user