<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>209522</bug_id>
          
          <creation_ts>2020-03-24 16:54:31 -0700</creation_ts>
          <short_desc>[Cocoa] Avoid logging sensitive information for all network sessions</short_desc>
          <delta_ts>2020-05-29 16:44:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <see_also>https://bugs.webkit.org/show_bug.cgi?id=212551</see_also>
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>211266</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Brent Fulgham">bfulgham</reporter>
          <assigned_to name="Brent Fulgham">bfulgham</assigned_to>
          <cc>achristensen</cc>
    
    <cc>bfulgham</cc>
    
    <cc>pvollan</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>wilander</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1633661</commentid>
    <comment_count>0</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-03-24 16:54:31 -0700</bug_when>
    <thetext>We avoid logging sensitive information (such as visited URLs) on production builds and for ephemeral sessions.

We should also avoid such logging for engineering and prerelease builds to reduce the possibility of personally identifiable information being retained in logs.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1633662</commentid>
    <comment_count>1</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-03-24 16:56:17 -0700</bug_when>
    <thetext>&lt;rdar://problem/54807157&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1633663</commentid>
    <comment_count>2</comment_count>
      <attachid>394442</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-03-24 16:58:15 -0700</bug_when>
    <thetext>Created attachment 394442
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1633759</commentid>
    <comment_count>3</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-03-24 20:34:39 -0700</bug_when>
    <thetext>The Windows test case failure is not related to this Cocoa-only change.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1633935</commentid>
    <comment_count>4</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2020-03-25 10:27:07 -0700</bug_when>
    <thetext>Committed r258994: &lt;https://trac.webkit.org/changeset/258994&gt;

All reviewed patches have been landed. Closing bug and clearing flags on attachment 394442.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>394442</attachid>
            <date>2020-03-24 16:58:15 -0700</date>
            <delta_ts>2020-03-25 10:27:07 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-209522-20200324165814.patch</filename>
            <type>text/plain</type>
            <size>2409</size>
            <attacher name="Brent Fulgham">bfulgham</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjU4OTU3CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IDA1MzUyYzYxMGY4Yzc3MjRl
Mjc1YjJmNWNkMjY5YWZmYjgzMDc2ZGEuLjEwNDE4MGRlZDBkNzkyY2FlNjA4MzRiYzZlMTg2MDMw
NWY2MGJjNWYgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTkgQEAKKzIwMjAtMDMtMjQgIEJyZW50IEZ1
bGdoYW0gIDxiZnVsZ2hhbUBhcHBsZS5jb20+CisKKyAgICAgICAgQXZvaWQgbG9nZ2luZyBzZW5z
aXRpdmUgaW5mb3JtYXRpb24gZm9yIGFsbCBuZXR3b3JrIHNlc3Npb25zCisgICAgICAgIGh0dHBz
Oi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMDk1MjIKKyAgICAgICAgPHJkYXI6
Ly9wcm9ibGVtLzU0ODA3MTU3PgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEp
LgorCisgICAgICAgIFdlIGF2b2lkIGxvZ2dpbmcgc2Vuc2l0aXZlIGluZm9ybWF0aW9uIChzdWNo
IGFzIHZpc2l0ZWQgVVJMcykgb24gcHJvZHVjdGlvbiBidWlsZHMgYW5kIGZvciBlcGhlbWVyYWwg
c2Vzc2lvbnMuCisKKyAgICAgICAgV2Ugc2hvdWxkIGFsc28gYXZvaWQgc3VjaCBsb2dnaW5nIGZv
ciBlbmdpbmVlcmluZyBhbmQgcHJlcmVsZWFzZSBidWlsZHMgdG8gcmVkdWNlIHRoZSBwb3NzaWJp
bGl0eSBvZiBhbnkKKyAgICAgICAgcGVyc29uYWxseSBpZGVudGlmaWFibGUgaW5mb3JtYXRpb24g
YmVpbmcgcmV0YWluZWQgaW4gbG9ncy4KKworICAgICAgICAqIE5ldHdvcmtQcm9jZXNzL2NvY29h
L05ldHdvcmtTZXNzaW9uQ29jb2EubW06CisgICAgICAgIChXZWJLaXQ6OmNvbmZpZ3VyYXRpb25G
b3JTZXNzaW9uSUQpOiBEZW55IHNlbnN0aXZlIGxvZ2dpbmcgZm9yIGFsbCBzZXNzaW9ucy4KKwog
MjAyMC0wMy0yNCAgUGVyIEFybmUgVm9sbGFuICA8cHZvbGxhbkBhcHBsZS5jb20+CiAKICAgICAg
ICAgW0NvY29hXSBGaXggbGF1bmNoIHRpbWUgcmVncmVzc2lvbiB3aXRoIENGIHByZWZzIGRpcmVj
dCBtb2RlIGVuYWJsZWQKZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQvTmV0d29ya1Byb2Nlc3Mv
Y29jb2EvTmV0d29ya1Nlc3Npb25Db2NvYS5tbSBiL1NvdXJjZS9XZWJLaXQvTmV0d29ya1Byb2Nl
c3MvY29jb2EvTmV0d29ya1Nlc3Npb25Db2NvYS5tbQppbmRleCA4MmU2ZmZkMThhM2JjZDhhMTRl
NGExODkwZmI1NDkyNjljOGI0MjUyLi5lODdjODY4ZjdhOTBhYzhkMmM3NmMwNzVjM2Y4N2FmNTI1
YjQ2YTliIDEwMDY0NAotLS0gYS9Tb3VyY2UvV2ViS2l0L05ldHdvcmtQcm9jZXNzL2NvY29hL05l
dHdvcmtTZXNzaW9uQ29jb2EubW0KKysrIGIvU291cmNlL1dlYktpdC9OZXR3b3JrUHJvY2Vzcy9j
b2NvYS9OZXR3b3JrU2Vzc2lvbkNvY29hLm1tCkBAIC05OTQsMTUgKzk5NCwxNyBAQCBzdGF0aWMg
Ym9vbCBzZXNzaW9uc0NyZWF0ZWQgPSBmYWxzZTsKIAogc3RhdGljIE5TVVJMU2Vzc2lvbkNvbmZp
Z3VyYXRpb24gKmNvbmZpZ3VyYXRpb25Gb3JTZXNzaW9uSUQoY29uc3QgUEFMOjpTZXNzaW9uSUQm
IHNlc3Npb24pCiB7CisgICAgTlNVUkxTZXNzaW9uQ29uZmlndXJhdGlvbiAqY29uZmlndXJhdGlv
bjsKICAgICBpZiAoc2Vzc2lvbi5pc0VwaGVtZXJhbCgpKSB7Ci0gICAgICAgIE5TVVJMU2Vzc2lv
bkNvbmZpZ3VyYXRpb24gKmNvbmZpZ3VyYXRpb24gPSBbTlNVUkxTZXNzaW9uQ29uZmlndXJhdGlv
biBlcGhlbWVyYWxTZXNzaW9uQ29uZmlndXJhdGlvbl07CisgICAgICAgIGNvbmZpZ3VyYXRpb24g
PSBbTlNVUkxTZXNzaW9uQ29uZmlndXJhdGlvbiBlcGhlbWVyYWxTZXNzaW9uQ29uZmlndXJhdGlv
bl07CiAgICAgICAgIGNvbmZpZ3VyYXRpb24uX3Nob3VsZFNraXBQcmVmZXJyZWRDbGllbnRDZXJ0
aWZpY2F0ZUxvb2t1cCA9IFlFUzsKKyAgICB9IGVsc2UKKyAgICAgICAgY29uZmlndXJhdGlvbiA9
IFtOU1VSTFNlc3Npb25Db25maWd1cmF0aW9uIGRlZmF1bHRTZXNzaW9uQ29uZmlndXJhdGlvbl07
CisKICNpZiBIQVZFKEFMTE9XU19TRU5TSVRJVkVfTE9HR0lORykKLSAgICAgICAgY29uZmlndXJh
dGlvbi5fYWxsb3dzU2Vuc2l0aXZlTG9nZ2luZyA9IE5POworICAgIGNvbmZpZ3VyYXRpb24uX2Fs
bG93c1NlbnNpdGl2ZUxvZ2dpbmcgPSBOTzsKICNlbmRpZgotICAgICAgICByZXR1cm4gY29uZmln
dXJhdGlvbjsKLSAgICB9Ci0gICAgcmV0dXJuIFtOU1VSTFNlc3Npb25Db25maWd1cmF0aW9uIGRl
ZmF1bHRTZXNzaW9uQ29uZmlndXJhdGlvbl07CisgICAgcmV0dXJuIGNvbmZpZ3VyYXRpb247CiB9
CiAKIGNvbnN0IFN0cmluZyYgTmV0d29ya1Nlc3Npb25Db2NvYTo6Ym91bmRJbnRlcmZhY2VJZGVu
dGlmaWVyKCkgY29uc3QK
</data>

          </attachment>
      

    </bug>

</bugzilla>