microsoft/restler-fuzzer

Trace database requests include authorization token

wilbaker opened this issue · 0 comments

Description

When the trace database is enabled, authorization tokens included in requests are being logged in plain text. They should be replaced with _OMITTED_AUTH_TOKEN_ (like the network logs).

Steps to reproduce

  1. Set use_trace_database to true in engine settings
  2. Specify an authentication token module in settings
  3. Run RESTler against service

Expected results

Tokens values are replaced with _OMITTED_AUTH_TOKEN_

Actual results

Token values are logged in plain text.

Environment details

RESTler version 9.2.4