Skip to content

[Security] Stop logging the app logs subscription token - #8750

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
security-maintenance-37247687073
Draft

github-actions[bot] wants to merge 1 commit into
mainfrom
security-maintenance-37247687073

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

WHY are these changes introduced?

Subscribing to app logs returns a JWT that acts as a bearer credential for that app's log stream. It was written verbatim to debug output, so it was captured by any --verbose session — exactly the output developers routinely paste into issue reports and support threads. This is a sensitive-data-in-logs issue in the app logs subscription path.

The debug line immediately below already reports that the subscription succeeded, so the token value itself carried no diagnostic information.

WHAT is this pull request doing?

Removes the debug line that printed the subscription token in packages/app/src/cli/services/app-logs/utils.ts. The surrounding debug output (API key, subscribed shop IDs, success flag) is unchanged, and the token is still returned to callers exactly as before, so app dev and app logs behave identically.

Adds a focused regression test asserting the token never appears in debug output.

How to manually test your changes?

shopify app logs --verbose
shopify app dev --verbose

Log streaming works as before, and the verbose output no longer contains the subscription token.

Checklist

  • I've considered possible cross-platform impacts (Mac, Linux, Windows)
  • I've considered possible documentation changes
  • I've considered analytics changes to measure impact
  • The change is user-facing — I've identified the correct bump type (patch for bug fixes · minor for new features · major for breaking changes) and added a changeset with pnpm changeset add

The app logs subscription JWT was written verbatim to debug output, so it
landed in any `--verbose` session a developer might share when reporting an
issue. The adjacent debug line already confirms the subscription succeeded,
so the token itself carries no diagnostic value.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants