lib/Controller/BreachProxyController.php line 195 logs 'Keepiq: HIBP range lookup failed: ' . $e->getMessage(). When the HTTP client throws, its message carries the request URL, https://api.pwnedpasswords.com/range/<prefix>. Nextcloud stamps every log line with the requesting user, so nextcloud.log ends up holding a user id beside the first five hex characters of a SHA-1 of a password they typed. The comment one line above says that pairing must never happen.
The prefix alone is k-anonymous. Paired with a user and a time, it narrows that user's password to one of a few hundred hashes in the range. Anyone who can read the log gets that.
Found while adopting the connection registry (#706). That PR does not change the log line, and its connection report only ever carries the HTTP status.
What to do
- Log the exception class and, when there is one, the HTTP status. Never
getMessage().
- Add a test that throws an exception whose message contains a prefix and asserts the logged message does not.
Done when no log line written by the breach proxy can contain the prefix.
🤖 Generated with Claude Code
lib/Controller/BreachProxyController.phpline 195 logs'Keepiq: HIBP range lookup failed: ' . $e->getMessage(). When the HTTP client throws, its message carries the request URL,https://api.pwnedpasswords.com/range/<prefix>. Nextcloud stamps every log line with the requesting user, sonextcloud.logends up holding a user id beside the first five hex characters of a SHA-1 of a password they typed. The comment one line above says that pairing must never happen.The prefix alone is k-anonymous. Paired with a user and a time, it narrows that user's password to one of a few hundred hashes in the range. Anyone who can read the log gets that.
Found while adopting the connection registry (#706). That PR does not change the log line, and its connection report only ever carries the HTTP status.
What to do
getMessage().Done when no log line written by the breach proxy can contain the prefix.
🤖 Generated with Claude Code