Comments (4)
all configuration for the securrity logging library now is done now with xml, but it can also be done with annotations. Here is an example of what i mean : https://projectlombok.org/features/log. If you can annotate a property with say @Masked it would only show up in logs as masked value (f.i. last 4 numbers of a credit card). Those are the features i am thinking of.
from owasp-security-logging.
Hi @javabeanz. Please provide a little more detail for the benefits of logging annotations and aspects so we understand what you propose. So for example, what annotations do you suggest and what do they do? Also for AOP, what aspects should we create and where should they be bound? Thanks. --Milton
from owasp-security-logging.
I like this idea. Developers could annotate properties of their classes and prevent them from being logged incidentally (e.g. if MyBean.toString()
is called).
from owasp-security-logging.
from owasp-security-logging.
Related Issues (20)
- CVE-502 vuln for log4j2 version HOT 2
- poms still on old version 1.1.4 HOT 1
- Replacement for VersionEye HOT 1
- Feature : covert logging HOT 1
- Exclude tests from code quality report HOT 5
- Boost Codacy score
- investigate alternative quality platforms
- Masking not working with logback in spring boot HOT 4
- Log injection is possible in exception messages with CRLFConverter HOT 1
- Travis not running HOT 2
- Logback log injection HOT 6
- Doesn't work with Spring Boot HOT 3
- is the new trojan source hack relevant for security logging ?
- Add documentation about a good way to disable masking during debugging
- investigate RCE impact zero day Log4j HOT 5
- CVE-2021-45046
- Update to logback 1.28 HOT 2
- Logback converter for Backspace character HOT 3
- security-logging-logback is not compatible with logback-classic version 1.3.x (partially) HOT 3
- Release Latest Version of owasp-security-logging with Recent Updates
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from owasp-security-logging.