Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable filtering of request query strings using ActiveSupport::ParameterFilter. #111

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

steventux
Copy link

PII can leak into DfE analytics if present in the request query string, a common case is search parameters using personal details.

This PR adds the ability to enable web request event query filtering using the standard Rails parameter filter mechanism via the DfE::Analytics.filter_web_request_events configuration value.

See: DFE-Digital/access-your-teaching-qualifications@5941285 for a common workaround currently being used in services to mitigate this.

It would be preferable not to replicate this workaround on a per-service basis.

Adds a configurable web_request event query string filter via ActiveSupport::ParameterFilter mechanism.
@steventux
Copy link
Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant