From ecf6b0b8664672851251afc50f634ebb107571fb Mon Sep 17 00:00:00 2001 From: Chong Jia Zhen <110578271+chongjiazhen@users.noreply.github.com> Date: Tue, 1 Sep 2026 14:36:46 +0800 Subject: [PATCH] fix(channels): silence httpx request logging so bot tokens stay out of logs python-telegram-bot performs its API calls through httpx, and the Telegram bot token is embedded in the request URL. httpx logs one line per request at INFO level, so both worker entrypoints wrote the token to their logs in plaintext on every poll: httpx - INFO - HTTP Request: GET https://api.telegram.org/bot123456:AAFAKE-TOKEN-abcdef/getMe "HTTP/1.1 401 Unauthorized" Raise the httpx and httpcore loggers to WARNING in the two entrypoints that call logging.basicConfig. channel_worker runs the adapters directly; worker_service reaches the same code path through the messaging tools (core/tools/messaging.py imports telegram_adapter to deliver reach-outs). Worker-level INFO logging is unaffected. Assisted by AI. --- services/channel_worker.py | 5 +++++ services/worker_service.py | 5 +++++ 2 files changed, 10 insertions(+) diff --git a/services/channel_worker.py b/services/channel_worker.py index 8288c1b1..b5a43cd9 100644 --- a/services/channel_worker.py +++ b/services/channel_worker.py @@ -32,6 +32,11 @@ level=logging.INFO, format="%(asctime)s - %(name)s - %(levelname)s - %(message)s", ) +# python-telegram-bot issues its API calls through httpx, and the bot token +# is part of the request URL. httpx logs a line per request at INFO, so +# leaving it enabled writes the token to the logs in plaintext. +logging.getLogger("httpx").setLevel(logging.WARNING) +logging.getLogger("httpcore").setLevel(logging.WARNING) logger = logging.getLogger("channel_worker") CHANNEL_CONFIG_POLL_INTERVAL_S = float( diff --git a/services/worker_service.py b/services/worker_service.py index 63e8f3d9..f059c818 100644 --- a/services/worker_service.py +++ b/services/worker_service.py @@ -62,6 +62,11 @@ level=logging.INFO, format="%(asctime)s - %(name)s - %(levelname)s - %(message)s", ) +# python-telegram-bot issues its API calls through httpx, and the bot token +# is part of the request URL. httpx logs a line per request at INFO, so +# leaving it enabled writes the token to the logs in plaintext. +logging.getLogger("httpx").setLevel(logging.WARNING) +logging.getLogger("httpcore").setLevel(logging.WARNING) logger = logging.getLogger("heartbeat_worker") POLL_INTERVAL = float(os.getenv("WORKER_POLL_INTERVAL", 1.0))