Skip to content

Securiy Patch: Patched a potential security flaw with logs#76

Merged
Zalmez merged 4 commits intomainfrom
security/fix_log_weakness
Dec 4, 2025
Merged

Securiy Patch: Patched a potential security flaw with logs#76
Zalmez merged 4 commits intomainfrom
security/fix_log_weakness

Conversation

@Zalmez
Copy link
Owner

@Zalmez Zalmez commented Nov 28, 2025

No description provided.

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This security patch introduces a LogSanitizer utility class to prevent log injection attacks by sanitizing user-controlled data before it is written to logs. The sanitizer removes control characters and escapes newlines, ensuring that attackers cannot forge log entries or hide malicious activity through crafted input containing newline characters.

Key changes:

  • Added LogSanitizer.Sanitize() method that removes control characters and converts CR/LF to visible escape sequences
  • Applied sanitization to all log statements that include user-controlled data (dashboard titles, section names, button text, API responses, URLs)
  • Protected against log injection vulnerabilities across multiple controllers

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
Dashy.Net.ApiService/Infrastructure/LogSanitizer.cs New utility class that sanitizes values for safe logging by removing control characters and escaping newlines
Dashy.Net.ApiService/Controllers/WeatherController.cs Sanitizes external API URLs and error responses before logging
Dashy.Net.ApiService/Controllers/SectionsController.cs Sanitizes section names (user input) in create and delete log statements
Dashy.Net.ApiService/Controllers/HeaderButtonsController.cs Sanitizes header button text (user input) in create log statement
Dashy.Net.ApiService/Controllers/DashboardController.cs Sanitizes dashboard title (user input) in create log statement

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Zalmez and others added 3 commits November 28, 2025 01:52
… user input

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Cato Myhre <catomyhre@outlook.com>
@Zalmez Zalmez merged commit 0cd2dac into main Dec 4, 2025
9 checks passed
@Zalmez Zalmez deleted the security/fix_log_weakness branch December 4, 2025 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants