Skip to content

fix(vehicles): show only a VIN's last four characters in logs - #158

Merged
frahlg merged 2 commits into
mainfrom
143-mask-vin-in-logs
Oct 4, 2026
Merged

frahlg merged 2 commits into
mainfrom
143-mask-vin-in-logs

Conversation

@frahlg

@frahlg frahlg commented Oct 4, 2026

Copy link
Copy Markdown
Member

Problem

A full VIN reached a public issue (#143) through a pasted vag_vehicle log line. The driver logged the VIN at start, and in every reading through the dataset file name (<time>_<VIN>.zip). tesla_vehicle, tesla_cloud and teslamate_vehicle also log it at start, and tesla_cloud in two debug lines. People paste logs when they ask for help, so it will happen again.

Change

  • Each of the four drivers sends every log line through one local log function that replaces the VIN with ****1234. API errors that quote a URL with the VIN are masked too.
  • The VIN is still used in full for API calls and as the serial (host.set_sn).
  • The tesla_cloud and vag_vehicle harnesses fail on any log line that holds the full VIN. The VAG fake portal now names files as the real one does.
  • Patch bumps: vag_vehicle 0.2.1, tesla_vehicle 0.2.4, tesla_cloud 0.1.1, teslamate_vehicle 0.1.1.

Test

  • make check: 4808 passed, 923 skipped.
  • With the old tesla_cloud.lua and vag_vehicle.lua, both harnesses fail on the start log line (log shows the full VIN).
  • Not run on hardware or against a live car. The change touches log text only.

FTW's bundled snapshot keeps the old drivers until the pin moves.

🤖 Generated with Claude Code

A full VIN reached a public issue (#143) through a pasted vag_vehicle
log line: the driver logged the VIN at start and in every dataset file
name. tesla_vehicle, tesla_cloud and teslamate_vehicle also logged it.

Each of the four drivers now sends every log line through one local
function that replaces the VIN with ****1234, so API errors that quote
a URL with the VIN are masked too. The VIN is still used in full for
API calls and as the serial.

The tesla_cloud and vag_vehicle harnesses fail on any log line that
holds the full VIN, and the VAG fake portal now names files as the real
one does, <time>_<VIN>.zip. Both harnesses fail against the old drivers.

Patch bumps: vag_vehicle 0.2.1, tesla_vehicle 0.2.4, tesla_cloud 0.1.1,
teslamate_vehicle 0.1.1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-04T07:45:58.587340Z c05b18b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Signed-off-by: Fredrik Ahlgren <fredrik@sourceful-labs.com>

# Conflicts:
#	CHANGELOG.md
@frahlg
frahlg merged commit 3f5cb88 into main Oct 4, 2026
5 checks passed
@frahlg
frahlg deleted the 143-mask-vin-in-logs branch October 4, 2026 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant