fix(channels): silence httpx request logging so bot tokens stay out of logs - #143
chongjiazhen wants to merge 1 commit into
Conversation
…f logs
python-telegram-bot performs its API calls through httpx, and the Telegram
bot token is embedded in the request URL. httpx logs one line per request
at INFO level, so both worker entrypoints wrote the token to their logs in
plaintext on every poll:
httpx - INFO - HTTP Request: GET
https://api.telegram.org/bot123456:AAFAKE-TOKEN-abcdef/getMe "HTTP/1.1 401 Unauthorized"
Raise the httpx and httpcore loggers to WARNING in the two entrypoints that
call logging.basicConfig. channel_worker runs the adapters directly;
worker_service reaches the same code path through the messaging tools
(core/tools/messaging.py imports telegram_adapter to deliver reach-outs).
Worker-level INFO logging is unaffected.
Assisted by AI.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughBoth worker services now set the ChangesRequest logging suppression
Estimated code review effort: 1 (Trivial) | ~5 minutes Merge Risk: ⚪ Minimal · up to The change prevents Telegram bot tokens from appearing in routine HTTP request logs while preserving warning and error visibility; no actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2 files. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Problem
python-telegram-botperforms its API calls throughhttpx, and the Telegram bot token is part of the request URL.httpxlogs one line per request atINFO, and both worker entrypoints calllogging.basicConfig(level=logging.INFO, ...)- so the token is written to the logs in plaintext on every long-poll.Reproduced against httpx 0.28.1:
Long-polling means this repeats continuously for the life of the worker, so any log capture, shipped log, or pasted troubleshooting output carries a working bot token.
Fix
Raise the
httpxandhttpcoreloggers toWARNINGin the two entrypoints that ownlogging.basicConfig:services/channel_worker.py- runs the channel adapters directly.services/worker_service.py- reaches the same code path through the messaging tools (core/tools/messaging.pyimportschannels.telegram_adapterto deliver reach-outs).Real errors still surface:
WARNINGand above are unaffected, as is every Hexis-owned logger.Verification
With the guard in place, the request line is gone and the worker's own logging is untouched:
Removing the two
setLevellines brings the token line back, so the guard is doing the work rather than passing vacuously.python -m py_compileclean on both files. No behavior change beyond log verbosity; no new dependencies.Assisted by AI.
Summary by CodeRabbit