<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>196831</bug_id>
          
          <creation_ts>2019-04-11 14:45:30 -0700</creation_ts>
          <short_desc>Always set _allowsSensitiveLogging to NO</short_desc>
          <delta_ts>2019-04-15 13:15:22 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Saam Barati">saam</reporter>
          <assigned_to name="Saam Barati">saam</assigned_to>
          <cc>achristensen</cc>
    
    <cc>ggaren</cc>
    
    <cc>jberlin</cc>
    
    <cc>krollin</cc>
    
    <cc>mjs</cc>
    
    <cc>rniwa</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1526475</commentid>
    <comment_count>0</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2019-04-11 14:45:30 -0700</bug_when>
    <thetext>...</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1526479</commentid>
    <comment_count>1</comment_count>
      <attachid>367243</attachid>
    <who name="Saam Barati">saam</who>
    <bug_when>2019-04-11 14:52:08 -0700</bug_when>
    <thetext>Created attachment 367243
patch

Hopefully it builds. I still need to test it.

Based on the documentation in:
https://developer.apple.com/documentation/foundation/nsurlsessionconfiguration/1411560-defaultsessionconfiguration?language=objc

&quot;Modifying the returned session configuration object does not affect any configuration objects returned by future calls to this method, and does not change the default behavior for existing sessions. It is therefore always safe to use the returned object as a starting point for additional customization.&quot;

I think this patch is safe to do without affecting other users of &quot;defaultSessionConfiguration&quot;.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1527353</commentid>
    <comment_count>2</comment_count>
    <who name="Alex Christensen">achristensen</who>
    <bug_when>2019-04-15 13:15:22 -0700</bug_when>
    <thetext>(In reply to Saam Barati from comment #1)
&gt; Created attachment 367243 [details]
&gt; I think this patch is safe to do without affecting other users of
&gt; &quot;defaultSessionConfiguration&quot;.
There are no other users of defaultSessionConfiguration in the network process.  This patch will disallow sensitive logging in all WKWebViews and have no other effects.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>367243</attachid>
            <date>2019-04-11 14:52:08 -0700</date>
            <delta_ts>2019-04-11 15:38:00 -0700</delta_ts>
            <desc>patch</desc>
            <filename>c-backup.diff</filename>
            <type>text/plain</type>
            <size>1958</size>
            <attacher name="Saam Barati">saam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyNDQxOTUpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDEzIEBACisyMDE5LTA0LTExICBTYWFtIGJhcmF0
aSAgPHNiYXJhdGlAYXBwbGUuY29tPgorCisgICAgICAgIEFsd2F5cyBzZXQgX2FsbG93c1NlbnNp
dGl2ZUxvZ2dpbmcgdG8gTk8KKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19i
dWcuY2dpP2lkPTE5NjgzMQorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgor
CisgICAgICAgICogTmV0d29ya1Byb2Nlc3MvY29jb2EvTmV0d29ya1Nlc3Npb25Db2NvYS5tbToK
KyAgICAgICAgKFdlYktpdDo6Y29uZmlndXJhdGlvbkZvclNlc3Npb25JRCk6CisKIDIwMTktMDQt
MTEgIEFudHRpIEtvaXZpc3RvICA8YW50dGlAYXBwbGUuY29tPgogCiAgICAgICAgIFJFR1JFU1NJ
T046IGNoYW5naW5nIGlQYWQgb3JpZW50YXRpb24gb24gYmxvZ2dlci5jb20gY3Jhc2hlcyB1bmRl
ciBSZW1vdGVTY3JvbGxpbmdDb29yZGluYXRvclByb3h5Ojplc3RhYmxpc2hMYXllclRyZWVTY3Jv
bGxpbmdSZWxhdGlvbnMoKQpJbmRleDogU291cmNlL1dlYktpdC9OZXR3b3JrUHJvY2Vzcy9jb2Nv
YS9OZXR3b3JrU2Vzc2lvbkNvY29hLm1tCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJLaXQvTmV0
d29ya1Byb2Nlc3MvY29jb2EvTmV0d29ya1Nlc3Npb25Db2NvYS5tbQkocmV2aXNpb24gMjQ0MTk1
KQorKysgU291cmNlL1dlYktpdC9OZXR3b3JrUHJvY2Vzcy9jb2NvYS9OZXR3b3JrU2Vzc2lvbkNv
Y29hLm1tCSh3b3JraW5nIGNvcHkpCkBAIC04MDYsMTUgKzgwNiwxOCBAQCBzdGF0aWMgYm9vbCBz
ZXNzaW9uc0NyZWF0ZWQgPSBmYWxzZTsKIAogc3RhdGljIE5TVVJMU2Vzc2lvbkNvbmZpZ3VyYXRp
b24gKmNvbmZpZ3VyYXRpb25Gb3JTZXNzaW9uSUQoY29uc3QgUEFMOjpTZXNzaW9uSUQmIHNlc3Np
b24pCiB7CisgICAgTlNVUkxTZXNzaW9uQ29uZmlndXJhdGlvbiAqY29uZmlndXJhdGlvbjsKICAg
ICBpZiAoc2Vzc2lvbi5pc0VwaGVtZXJhbCgpKSB7Ci0gICAgICAgIE5TVVJMU2Vzc2lvbkNvbmZp
Z3VyYXRpb24gKmNvbmZpZ3VyYXRpb24gPSBbTlNVUkxTZXNzaW9uQ29uZmlndXJhdGlvbiBlcGhl
bWVyYWxTZXNzaW9uQ29uZmlndXJhdGlvbl07CisgICAgICAgIGNvbmZpZ3VyYXRpb24gPSBbTlNV
UkxTZXNzaW9uQ29uZmlndXJhdGlvbiBlcGhlbWVyYWxTZXNzaW9uQ29uZmlndXJhdGlvbl07CiAg
ICAgICAgIGNvbmZpZ3VyYXRpb24uX3Nob3VsZFNraXBQcmVmZXJyZWRDbGllbnRDZXJ0aWZpY2F0
ZUxvb2t1cCA9IFlFUzsKKyAgICB9IGVsc2UKKyAgICAgICAgY29uZmlndXJhdGlvbiA9IFtOU1VS
TFNlc3Npb25Db25maWd1cmF0aW9uIGRlZmF1bHRTZXNzaW9uQ29uZmlndXJhdGlvbl07CisKICNp
ZiBIQVZFKEFMTE9XU19TRU5TSVRJVkVfTE9HR0lORykKLSAgICAgICAgY29uZmlndXJhdGlvbi5f
YWxsb3dzU2Vuc2l0aXZlTG9nZ2luZyA9IE5POworICAgIGNvbmZpZ3VyYXRpb24uX2FsbG93c1Nl
bnNpdGl2ZUxvZ2dpbmcgPSBOTzsKICNlbmRpZgotICAgICAgICByZXR1cm4gY29uZmlndXJhdGlv
bjsKLSAgICB9Ci0gICAgcmV0dXJuIFtOU1VSTFNlc3Npb25Db25maWd1cmF0aW9uIGRlZmF1bHRT
ZXNzaW9uQ29uZmlndXJhdGlvbl07CisKKyAgICByZXR1cm4gY29uZmlndXJhdGlvbjsKIH0KIAog
Y29uc3QgU3RyaW5nJiBOZXR3b3JrU2Vzc2lvbkNvY29hOjpzb3VyY2VBcHBsaWNhdGlvbkJ1bmRs
ZUlkZW50aWZpZXIoKSBjb25zdAo=
</data>

          </attachment>
      

    </bug>

</bugzilla>