FeatureFuel
1

Warm users about access key leakage in access logs

Source: dani-garcia/vaultwarden#4631 · opened by @rwjack
Not really a bug, but I think the docs should provide info about this:

I just saw that from v1.29.0, WSS is enabled by default, which means all access tokens and encrypted data is being stored in plaintext in reverse proxy access logs, unless the proxy is configured to filter out such requests.

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests