Skip to content

Commit 9ffecd5

Browse files
authored
Merge pull request #364 from AzureAD/redact-id-token-from-debug-log
Also redact id token from now on
2 parents 0c15c75 + a5a6b90 commit 9ffecd5

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

msal/token_cache.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ def wipe(dictionary, sensitive_fields): # Masks sensitive info
113113
return self.__add(event, now=now)
114114
finally:
115115
wipe(event.get("response", {}), ( # These claims were useful during __add()
116-
"access_token", "refresh_token", "username"))
116+
"access_token", "refresh_token", "id_token", "username"))
117117
wipe(event, ["username"]) # Needed for federated ROPC
118118
logger.debug("event=%s", json.dumps(
119119
# We examined and concluded that this log won't have Log Injection risk,

0 commit comments

Comments
 (0)