fix(vector-store): stop writing service account private key to DEBUG logs in GoogleMatchingEngine (#7506)

Co-authored-by: rupak-eng <rupak-eng@users.noreply.github.com>
This commit is contained in:
rupak
2026-10-07 16:20:38 +05:30
committed by GitHub
parent 0516f19f72
commit d62ce07fac
2 changed files with 35 additions and 2 deletions
@@ -1,3 +1,4 @@
import logging
from unittest.mock import Mock, patch
import pytest
@@ -165,3 +166,35 @@ def test_error_handling(vector_store, mock_vertex_ai):
assert isinstance(exc_info.value, exceptions.InvalidArgument)
assert "Invalid request" in str(exc_info.value)
def test_debug_logs_never_carry_service_account_key(caplog):
"""Regression for #7503: constructor DEBUG lines must not log the inline credential.
The constructor emits the whole kwargs dict and the validated config dump at
DEBUG; when ``service_account_json`` is passed inline that writes the PEM
private key to the log sink. Constructor diagnostics should name the fields,
never their values.
"""
private_key = "-----BEGIN PRIVATE KEY-----\nFAKE-KEY-MATERIAL-FOR-TEST\n-----END PRIVATE KEY-----\n"
kwargs = {
"project_id": "test-project",
"project_number": "123456789",
"region": "us-central1",
"endpoint_id": "test-endpoint",
"index_id": "test-index",
"deployment_index_id": "test-deployment",
"service_account_json": {"type": "service_account", "private_key": private_key},
}
with caplog.at_level(logging.DEBUG, logger="mem0.vector_stores.vertex_ai_vector_search"):
# Fails later at credential load (no network, no valid key); the two
# DEBUG statements under test run before that.
with pytest.raises(Exception):
GoogleMatchingEngine(**kwargs)
logged = caplog.text
assert private_key not in logged
assert "FAKE-KEY-MATERIAL-FOR-TEST" not in logged
# The diagnostics must stay useful: field names are still logged.
assert "service_account_json" in logged