Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Fix JWT tokens appearing in task logs by sunank200 · Pull Request #62782 · apache/airflow · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions airflow-core/newsfragments/62773.bugfix.rst
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
Fix JWT tokens appearing in task logs by redacting them in structlog and avoiding logging full workload objects.
28 changes: 25 additions & 3 deletions shared/logging/src/airflow_shared/logging/structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -203,11 +203,33 @@ def logger_name(logger: Any, method_name: Any, event_dict: EventDict) -> EventDi


# `eyJ` is `{"` in base64 encoding -- and any value that starts like that is very likely a JWT
# token. Better safe than sorry
# token. Better safe than sorry. We also redact token-bearing objects (e.g. workload) by dumping
# and recursively redacting sensitive keys and JWT strings so they never appear in logs.
_SENSITIVE_KEYS = frozenset({"token"})
_MAX_REDACT_DEPTH = 5


def _redact_value(val: Any, depth: int) -> Any:
"""Recursively redact JWTs in strings and sensitive key values in dicts; handle Pydantic-like objects."""
if depth > _MAX_REDACT_DEPTH:
return val
if isinstance(val, str):
return re.sub(JWT_PATTERN, "eyJ***", val)
if isinstance(val, dict):
return {k: "***" if k in _SENSITIVE_KEYS else _redact_value(v, depth + 1) for k, v in val.items()}
if isinstance(val, list):
return [_redact_value(x, depth + 1) for x in val]
if hasattr(val, "model_dump"):
try:
return _redact_value(val.model_dump(), depth)
except Exception:
return "<redacted>"
return val


def redact_jwt(logger: Any, method_name: str, event_dict: EventDict) -> EventDict:
for k, v in event_dict.items():
if isinstance(v, str):
event_dict[k] = re.sub(JWT_PATTERN, "eyJ***", v)
event_dict[k] = _redact_value(v, 0)
return event_dict


Expand Down
46 changes: 45 additions & 1 deletion shared/logging/tests/logging/test_structlog.py
Original file line numberDiff line numberDiff line change
Expand Up@@ -33,7 +33,10 @@
from structlog.processors import CallsiteParameter

from airflow_shared.logging import structlog as structlog_module
from airflow_shared.logging.structlog import configure_logging
from airflow_shared.logging.structlog import (
configure_logging,
redact_jwt,
)

# We don't want to use the caplog fixture in this test, as the main purpose of this file is to capture the
# _rendered_ output of the tests to make sure it is correct.
Expand DownExpand Up@@ -380,3 +383,44 @@ def test_logger_respects_configured_level(structlog_config):

written = sio.getvalue()
assert "[my_logger] Debug message\n" in written


def test_redact_jwt_redacts_string_with_jwt():
"""JWT-like strings are redacted to eyJ***."""
event_dict = {"event": "Auth", "token_str": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret"}
out = redact_jwt(None, "info", event_dict)
assert out["token_str"] == "eyJ***"


def test_redact_jwt_redacts_token_in_object_with_model_dump():
"""Values with model_dump() (e.g. Pydantic) have 'token' key and JWT strings redacted."""
event_dict = {"event": "Executing workload", "workload": None}
logger = None
method_name = "info"

class WorkloadLike:
def model_dump(self):
return {"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.secret", "dag_id": "my_dag"}

event_dict["workload"] = WorkloadLike()
out = redact_jwt(logger, method_name, event_dict)
assert out["workload"] == {"token": "***", "dag_id": "my_dag"}


def test_redact_jwt_replaces_non_dumpable_object_with_redacted():
"""Objects with model_dump() that raise are replaced with <redacted>."""

class BadDump:
def model_dump(self):
raise ValueError("nope")

event_dict = {"event": "x", "obj": BadDump()}
out = redact_jwt(None, "info", event_dict)
assert out["obj"] == "<redacted>"


def test_redact_jwt_unchanged_when_no_jwt_or_sensitive():
"""Event dict with plain strings and no workload is unchanged except no JWT to redact."""
event_dict = {"event": "Hello", "key1": "value1"}
out = redact_jwt(None, "info", event_dict)
assert out == event_dict
Original file line numberDiff line numberDiff line change
Expand Up@@ -53,7 +53,13 @@ def execute_workload(workload: ExecuteTask) -> None:
if not isinstance(workload, workloads.ExecuteTask):
raise ValueError(f"Executor does not know how to handle {type(workload)}")

log.info("Executing workload", workload=workload)
log.info(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You could keep the same logging statement here and instead set the JWT-containing attribute as a pydantic.SecretStr, which will by default redact the field from logs.

"Executing workload",
dag_id=workload.ti.dag_id,
task_id=workload.ti.task_id,
run_id=workload.ti.run_id,
log_path=workload.log_path,
)

base_url = conf.get("api", "base_url", fallback="/")
# If it's a relative URL, use localhost:8080 as the default
Expand Down
Loading