Skip to content

Fixed - RedisURI.toString() leaks password in plaintext in exception messages and logs. #7031 - #7032

Merged
mrniko merged 1 commit into
redisson:masterfrom
Woongi9:fix/redis-uri-password-masking
Apr 10, 2026
Merged

mrniko merged 1 commit into
redisson:masterfrom
Woongi9:fix/redis-uri-password-masking

Conversation

@Woongi9

@Woongi9 Woongi9 commented Apr 9, 2026

Copy link
Copy Markdown
Contributor

Fixed #7031

Problem

RedisURI.toString() was exposing credentials in plaintext in exception messages and log output.

Before
RedisConnectionException: Unable to connect to: redis://[email protected]:6379

After
RedisConnectionException: Unable to connect to: redis://***@prod.example.com:6379

Changes

  • RedisURI.toString(): mask username and password with ***
  • RedisURITest: added unit tests for masking behavior

@Woongi9
Woongi9 force-pushed the fix/redis-uri-password-masking branch from 299a264 to 3ced378 Compare April 9, 2026 13:59
@mrniko mrniko added this to the 4.3.2 milestone Apr 9, 2026
@mrniko
mrniko merged commit 42443a3 into redisson:master Apr 10, 2026
4 checks passed
@mrniko mrniko added the bug label Apr 10, 2026
@mrniko

mrniko commented Apr 10, 2026

Copy link
Copy Markdown
Member

Thanks for contribution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

RedisURI.toString() leaks password in plaintext in exception messages and logs

2 participants