Skip to content

fix(security): Drop personal data from service logs - #20

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-logging
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-logging

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

CodeQL py/clear-text-logging-sensitive-data flagged 30 log calls
that wrote employee identifiers, salary, gross pay, employer
burden, billing ids and corporate card numbers in clear text.
Logs leave the tenant boundary (aggregators, support access), so
these values do not belong there.

Remove only the flagged arguments; record ids, counts and
non-personal context stay so the logs remain useful. No business
logic changes.

🤖 Generated with Claude Code

CodeQL py/clear-text-logging-sensitive-data flagged 30 log calls
that wrote employee identifiers, salary, gross pay, employer
burden, billing ids and corporate card numbers in clear text.
Logs leave the tenant boundary (aggregators, support access), so
these values do not belong there.

Remove only the flagged arguments; record ids, counts and
non-personal context stay so the logs remain useful. No business
logic changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit bf4e586 into main Oct 6, 2026
6 of 7 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the fix/codeql-logging branch October 6, 2026 01:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant