From dde085a466813dccea870c09c622d6131764eee1 Mon Sep 17 00:00:00 2001 From: wizardchen Date: Wed, 26 Nov 2025 12:02:04 +0800 Subject: [PATCH] refactor: Sanitize log inputs in chunk and session handlers to enhance security --- internal/application/service/chunk.go | 4 ---- internal/handler/session/handler.go | 7 ++++--- 2 files changed, 4 insertions(+), 7 deletions(-) diff --git a/internal/application/service/chunk.go b/internal/application/service/chunk.go index 7f473cffa..2e526ce53 100644 --- a/internal/application/service/chunk.go +++ b/internal/application/service/chunk.go @@ -139,11 +139,7 @@ func (s *chunkService) ListChunksByKnowledgeID(ctx context.Context, knowledgeID func (s *chunkService) ListPagedChunksByKnowledgeID(ctx context.Context, knowledgeID string, page *types.Pagination, chunkType []types.ChunkType, ) (*types.PageResult, error) { - logger.Info(ctx, "Start listing paged chunks by knowledge ID") - logger.Infof(ctx, "Knowledge ID: %s, page: %d, page size: %d", knowledgeID, page.Page, page.PageSize) - tenantID := ctx.Value(types.TenantIDContextKey).(uint64) - logger.Infof(ctx, "Tenant ID: %d", tenantID) chunks, total, err := s.chunkRepository.ListPagedChunksByKnowledgeID(ctx, tenantID, knowledgeID, page, chunkType, "") if err != nil { logger.ErrorWithFields(ctx, err, map[string]interface{}{ diff --git a/internal/handler/session/handler.go b/internal/handler/session/handler.go index a6da8ff90..e0d5cf75c 100644 --- a/internal/handler/session/handler.go +++ b/internal/handler/session/handler.go @@ -9,6 +9,7 @@ import ( "github.com/Tencent/WeKnora/internal/logger" "github.com/Tencent/WeKnora/internal/types" "github.com/Tencent/WeKnora/internal/types/interfaces" + secutils "github.com/Tencent/WeKnora/internal/utils" "github.com/gin-gonic/gin" ) @@ -193,7 +194,7 @@ func (h *Handler) GetSession(c *gin.Context) { logger.Info(ctx, "Start retrieving session") // Get session ID from URL parameter - id := c.Param("id") + id := secutils.SanitizeForLog(c.Param("id")) if id == "" { logger.Error(ctx, "Session ID is empty") c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error())) @@ -257,7 +258,7 @@ func (h *Handler) UpdateSession(c *gin.Context) { ctx := c.Request.Context() // Get session ID from URL parameter - id := c.Param("id") + id := secutils.SanitizeForLog(c.Param("id")) if id == "" { logger.Error(ctx, "Session ID is empty") c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error())) @@ -308,7 +309,7 @@ func (h *Handler) DeleteSession(c *gin.Context) { ctx := c.Request.Context() // Get session ID from URL parameter - id := c.Param("id") + id := secutils.SanitizeForLog(c.Param("id")) if id == "" { logger.Error(ctx, "Session ID is empty") c.Error(errors.NewBadRequestError(errors.ErrInvalidSessionID.Error()))