From dec87e971a38c130cae21469ece5fe453ae2bf7f Mon Sep 17 00:00:00 2001 From: Shrinidhi Shastri Date: Fri, 20 Dec 2024 22:31:47 +0530 Subject: [PATCH] chore(templates): remove console.log that logs payload secret for security (#10095) I noticed that payload.secret was getting logged via console.log, adding a significant security risk. Removed the console.log statements from three preview/route.ts files. --- examples/draft-preview/src/app/(app)/next/preview/route.ts | 1 - templates/website/src/app/(frontend)/next/preview/route.ts | 1 - .../with-vercel-website/src/app/(frontend)/next/preview/route.ts | 1 - 3 files changed, 3 deletions(-) diff --git a/examples/draft-preview/src/app/(app)/next/preview/route.ts b/examples/draft-preview/src/app/(app)/next/preview/route.ts index 287b454c1f..da133e64d9 100644 --- a/examples/draft-preview/src/app/(app)/next/preview/route.ts +++ b/examples/draft-preview/src/app/(app)/next/preview/route.ts @@ -53,7 +53,6 @@ export async function GET( headers: req.headers, }) } catch (error) { - console.log({ token, payloadSecret: payload.secret }) payload.logger.error({ err: error }, 'Error verifying token for live preview') return new Response('You are not allowed to preview this page', { status: 403 }) } diff --git a/templates/website/src/app/(frontend)/next/preview/route.ts b/templates/website/src/app/(frontend)/next/preview/route.ts index 0a49f3ef77..80642637c0 100644 --- a/templates/website/src/app/(frontend)/next/preview/route.ts +++ b/templates/website/src/app/(frontend)/next/preview/route.ts @@ -51,7 +51,6 @@ export async function GET( headers: req.headers, }) } catch (error) { - console.log({ token, payloadSecret: payload.secret }) payload.logger.error({ err: error }, 'Error verifying token for live preview') return new Response('You are not allowed to preview this page', { status: 403 }) } diff --git a/templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts b/templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts index 0a49f3ef77..80642637c0 100644 --- a/templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts +++ b/templates/with-vercel-website/src/app/(frontend)/next/preview/route.ts @@ -51,7 +51,6 @@ export async function GET( headers: req.headers, }) } catch (error) { - console.log({ token, payloadSecret: payload.secret }) payload.logger.error({ err: error }, 'Error verifying token for live preview') return new Response('You are not allowed to preview this page', { status: 403 }) }