fix(vehicles): show only a VIN's last four characters in logs - #158
Merged
Merged
Conversation
A full VIN reached a public issue (#143) through a pasted vag_vehicle log line: the driver logged the VIN at start and in every dataset file name. tesla_vehicle, tesla_cloud and teslamate_vehicle also logged it. Each of the four drivers now sends every log line through one local function that replaces the VIN with ****1234, so API errors that quote a URL with the VIN are masked too. The VIN is still used in full for API calls and as the serial. The tesla_cloud and vag_vehicle harnesses fail on any log line that holds the full VIN, and the VAG fake portal now names files as the real one does, <time>_<VIN>.zip. Both harnesses fail against the old drivers. Patch bumps: vag_vehicle 0.2.1, tesla_vehicle 0.2.4, tesla_cloud 0.1.1, teslamate_vehicle 0.1.1. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com> # Conflicts: # CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A full VIN reached a public issue (#143) through a pasted
vag_vehiclelog line. The driver logged the VIN at start, and in every reading through the dataset file name (<time>_<VIN>.zip).tesla_vehicle,tesla_cloudandteslamate_vehiclealso log it at start, andtesla_cloudin two debug lines. People paste logs when they ask for help, so it will happen again.Change
logfunction that replaces the VIN with****1234. API errors that quote a URL with the VIN are masked too.host.set_sn).tesla_cloudandvag_vehicleharnesses fail on any log line that holds the full VIN. The VAG fake portal now names files as the real one does.vag_vehicle0.2.1,tesla_vehicle0.2.4,tesla_cloud0.1.1,teslamate_vehicle0.1.1.Test
make check: 4808 passed, 923 skipped.tesla_cloud.luaandvag_vehicle.lua, both harnesses fail on the start log line (log shows the full VIN).FTW's bundled snapshot keeps the old drivers until the pin moves.
🤖 Generated with Claude Code