我有一个Spring Boot网络应用程序,并使用logback作为我的日志记录解决方案。我一直在查看文档,找不到简单或正确的'屏蔽私人/特定数据的方式(个人信息,信用卡#等)。
我能找到的最接近的是Logback过滤器,但是围绕这些过滤器的用例似乎更多的是忽略符合特定条件的日志,我只是想掩盖所有应用程序范围的日志。
这似乎是一个基本问题,我确信我缺少一些超级基本的东西,但是对于正确方向的任何推动或指向都非常感激。
我也没有被锁定在logback中,所以如果有一个更容易/更好的方法来使用log4j2来做到这一点我就是耳朵
答案 0 :(得分:2)
要屏蔽可配置的字段,您需要像下面那样创建 MaskingPatternLayout
,
import java.util.Arrays;
import java.util.List;
import java.util.Optional;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
import ch.qos.logback.classic.PatternLayout;
import ch.qos.logback.classic.spi.ILoggingEvent;
public class MaskingPatternLayout extends PatternLayout {
private String patternsProperty;
private Optional<Pattern> pattern;
public String getPatternsProperty() {
return patternsProperty;
}
public void setPatternsProperty(String patternsProperty) {
this.patternsProperty = patternsProperty;
if (this.patternsProperty != null) {
this.pattern = Optional.of(Pattern.compile(patternsProperty, Pattern.MULTILINE));
} else {
this.pattern = Optional.empty();
}
}
@Override
public String doLayout(ILoggingEvent event) {
final StringBuilder message = new StringBuilder(super.doLayout(event));
if (pattern.isPresent()) {
Matcher matcher = pattern.get().matcher(message);
while (matcher.find()) {
int group = 1;
while (group <= matcher.groupCount()) {
if (matcher.group(group) != null) {
final int startGrpIndex = matcher.start(group);
final int endGrpIndex = matcher.end(group);
final int diff = endGrpIndex - startGrpIndex + 1;
int startIndex = startGrpIndex + diff;
final int endIndex1 = message.indexOf(",", startIndex);
final int endIndex2 = message.indexOf(" ", startIndex);
final int endIndex3 = message.indexOf(")", startIndex);
final int endIndex4 = message.indexOf("\n", startIndex);
final Integer endIndex = getSmallestInt(
Arrays.asList(Integer.valueOf(endIndex1), Integer.valueOf(endIndex2), Integer.valueOf(endIndex3), Integer.valueOf(endIndex4)));
if (endIndex == null || endIndex <= 0) {
continue;
}
for (int i = startIndex; i < endIndex; i++) {
message.setCharAt(i, '*');
}
}
group++;
}
}
}
return message.toString();
}
private Integer getSmallestInt(List<Integer> integerList) {
return integerList.stream().filter(integer -> integer > 0).reduce((x, y) -> x < y ? x : y).get();
}
}
需要在logback.xml appenders中添加编码器-
<encoder class="ch.qos.logback.core.encoder.LayoutWrappingEncoder">
<layout class="com.adgiants.config.MaskingPatternLayout">
<patternsProperty>(password)|(email)</patternsProperty>
<pattern>%d [%thread] %-5level %logger{35} - %msg%n</pattern>
</layout>
</encoder>
此配置将扫描您所有的日志语句并匹配“密码”或“电子邮件”(无论您在 logback.xml 编码器中配置的哪个)之类的词,其值将替换为 ****
例如
log.info("Received sign-up request, password=DummyPassword@123");
在日志中,上面的语句将显示为,
Received sign-up request, password=*****************