Skip to content

Commit

Permalink
filter sensitive controller parameters (#7124)
Browse files Browse the repository at this point in the history
  • Loading branch information
starswan authored Oct 3, 2024
1 parent 54c304b commit 8a17c43
Show file tree
Hide file tree
Showing 2 changed files with 50 additions and 0 deletions.
36 changes: 36 additions & 0 deletions config/initializers/filter_parameter_logging.rb
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,42 @@
gender
orientation
religion
id
job_title
jobseeker_id
jobseeker_profile_id
support_needed_details
rejection_reasons
further_instructions
job_application_id
publisher_id
first_name
last_name
previous_names
street_address
city
postcode
phone_number
institution
organisation
recipient_id
oid
main_duties
teacher_reference_number
finished_studying_details
close_relationships_details
gaps_in_employment_details
personal_statement
unconfirmed_email
family_name
given_name
email_address
about_you
name
application_email
contact_email
contact_number
qualification_results_attributes
] + [
/^age$/i,
]
Expand Down
14 changes: 14 additions & 0 deletions spec/configuration/filter_parameter_logging_spec.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
require "rails_helper"

RSpec.describe "Filter parameter logging configuration" do
let(:analytics_hidden_pii) { Rails.application.config_for(:analytics_hidden_pii) }
let(:filter_params) { Rails.application.config.filter_parameters }

specify "all anonymised analytics fields should be filtered from logs" do
analytics_hidden_pii.each_value do |shared|
shared.each do |field|
expect(filter_params).to include(field.to_sym)
end
end
end
end

0 comments on commit 8a17c43

Please sign in to comment.