<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Bug: API keys written to the error log in cleartext when using ?key= auth]]></title><description><![CDATA[<p dir="auto">When an API request using the ?key= query-string form throws, the Diagnostic Center records the full request URL including the key (e.g. Unhandled exception processing <a href="http://host:8622/api/json/?key=" rel="nofollow ugc">http://host:8622/api/json/?key=</a>...). The key is then readable by anyone with Diagnostic Center access or via LogMessages_GetMessages. Suggest redacting key when logging request URLs. (Workaround on our side: send the key as the X-ApiKey header instead.)</p>
]]></description><link>https://forums.inedo.com/topic/5807/bug-api-keys-written-to-the-error-log-in-cleartext-when-using-key-auth</link><generator>RSS for Node</generator><lastBuildDate>Thu, 06 Aug 2026 20:59:20 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5807.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 06 Aug 2026 17:47:42 GMT</pubDate><ttl>60</ttl></channel></rss>