Skip to content

fix(channels): silence httpx request logging so bot tokens stay out of logs - #143

Open
chongjiazhen wants to merge 1 commit into
QuixiAI:mainfrom
chongjiazhen:fix/silence-httpx-token-logging
Open

chongjiazhen wants to merge 1 commit into
QuixiAI:mainfrom
chongjiazhen:fix/silence-httpx-token-logging

Conversation

@chongjiazhen

@chongjiazhen chongjiazhen commented Sep 1, 2026 •

Copy link
Copy Markdown

Problem

python-telegram-bot performs its API calls through httpx, and the Telegram bot token is part of the request URL. httpx logs one line per request at INFO, and both worker entrypoints call logging.basicConfig(level=logging.INFO, ...) - so the token is written to the logs in plaintext on every long-poll.

Reproduced against httpx 0.28.1:

$ python -c "
import logging, httpx
logging.basicConfig(level=logging.INFO, format='%(name)s - %(levelname)s - %(message)s')
httpx.get('https://api.telegram.org/bot123456:AAFAKE-TOKEN-abcdef/getMe')
"
httpx - INFO - HTTP Request: GET https://api.telegram.org/bot123456:AAFAKE-TOKEN-abcdef/getMe "HTTP/1.1 401 Unauthorized"

Long-polling means this repeats continuously for the life of the worker, so any log capture, shipped log, or pasted troubleshooting output carries a working bot token.

Fix

Raise the httpx and httpcore loggers to WARNING in the two entrypoints that own logging.basicConfig:

  • services/channel_worker.py - runs the channel adapters directly.
  • services/worker_service.py - reaches the same code path through the messaging tools (core/tools/messaging.py imports channels.telegram_adapter to deliver reach-outs).

Real errors still surface: WARNING and above are unaffected, as is every Hexis-owned logger.

Verification

With the guard in place, the request line is gone and the worker's own logging is untouched:

2026-09-01 14:36:36,796 - channel_worker - INFO - worker still logs normally

Removing the two setLevel lines brings the token line back, so the guard is doing the work rather than passing vacuously.

python -m py_compile clean on both files. No behavior change beyond log verbosity; no new dependencies.

Assisted by AI.

Summary by CodeRabbit

  • Bug Fixes
    • Improved logging privacy by suppressing verbose HTTP request logs that could expose sensitive bot credentials.
    • Sensitive request URLs are no longer recorded in routine informational logs.

…f logs

python-telegram-bot performs its API calls through httpx, and the Telegram
bot token is embedded in the request URL. httpx logs one line per request
at INFO level, so both worker entrypoints wrote the token to their logs in
plaintext on every poll:

    httpx - INFO - HTTP Request: GET
    https://api.telegram.org/bot123456:AAFAKE-TOKEN-abcdef/getMe "HTTP/1.1 401 Unauthorized"

Raise the httpx and httpcore loggers to WARNING in the two entrypoints that
call logging.basicConfig. channel_worker runs the adapters directly;
worker_service reaches the same code path through the messaging tools
(core/tools/messaging.py imports telegram_adapter to deliver reach-outs).
Worker-level INFO logging is unaffected.

Assisted by AI.
@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: bf88783d-1962-4f16-9082-9d6b3382f38d

📥 Commits

Reviewing files that changed from the base of the PR and between 7423622 and ecf6b0b.

📒 Files selected for processing (2)
  • services/channel_worker.py
  • services/worker_service.py

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Both worker services now set the httpx and httpcore logger levels to WARNING. This suppresses INFO-level request logs that can include Telegram bot tokens in plaintext URLs.

Changes

Request logging suppression

Layer / File(s) Summary
Worker logger configuration
services/channel_worker.py, services/worker_service.py
The workers raise the httpx and httpcore logger levels to WARNING.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Merge Risk: ⚪ Minimal · up to ecf6b

The change prevents Telegram bot tokens from appearing in routine HTTP request logs while preserving warning and error visibility; no actionable merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: suppressing HTTP request logs to prevent Telegram bot tokens from appearing in logs.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2 files.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant