Skip to content

access_log

tit.server.access_log

Mask ?token= values in uvicorn's log lines.

The launcher's one-time GET /auth/session?token=… and the WebSocket ?token= fallback would otherwise print the shared secret into the access log (uvicorn.access) and the handshake log (uvicorn.error).

TokenMaskFilter

Bases: Filter

Rewrite token=<value> in the record's message and string args.

mask_token

mask_token(text: str) -> str

…?token=abc&x=1 → …?token=***&x=1.

Source code in tit/server/access_log.py
def mask_token(text: str) -> str:
    """``…?token=abc&x=1`` → ``…?token=***&x=1``."""
    return _TOKEN_RE.sub(MASK, text)