Skip to content

security(email): VPR-34 - Remove PII from email logs - #70

Merged
rlorenzo merged 3 commits into
mainfrom
VPR34-expose-private-data
Nov 21, 2025
Merged

rlorenzo merged 3 commits into
mainfrom
VPR34-expose-private-data

Conversation

@rlorenzo

Copy link
Copy Markdown
Contributor
  • Remove email addresses from all EmailService log output

- Remove email addresses from all EmailService log output
Copilot AI review requested due to automatic review settings November 19, 2025 02:13

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR removes personally identifiable information (PII) from email service logs by eliminating email addresses from all log statements in the EmailService class, addressing security ticket VPR-34.

Key Changes:

  • Removed recipient email addresses from all log output in SendEmailAsync method
  • Retained subject line and SMTP configuration details for debugging purposes
  • Applied changes consistently across information, error, and warning log levels

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread web/Services/EmailService.cs Fixed
Comment thread web/Services/EmailService.cs Fixed
- Remove email subjects from logs (potential sensitive data exposure)
- Add Area/Controller context to identify email trigger source
- Log recipient count instead of addresses for debugging
- Support background email tasks with "Background" context label

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated 2 comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread web/Services/EmailService.cs

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@rlorenzo
rlorenzo requested a review from bsedwards November 19, 2025 06:56
@rlorenzo
rlorenzo merged commit 5dcb9d1 into main Nov 21, 2025
11 checks passed
@rlorenzo
rlorenzo deleted the VPR34-expose-private-data branch November 21, 2025 00:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants