Commit b47a7273 authored by Stephane Nicoll's avatar Stephane Nicoll

Merge branch '1.5.x' into 2.0.x

parents 35c48bb9 5692b83a
......@@ -2358,6 +2358,22 @@ of how to register handlers in the servlet container.
[[howto-sanitize-sensible-values]]
=== Sanitize sensible values
Information returned by the `env` and `configprops` endpoints can be somewhat sensitive
so keys matching a certain pattern are sanitized by default (i.e. their values are
replaced by `******`).
Spring Boot uses sensible defaults for such keys: for instance, any key ending with the
word "password", "secret", "key" or "token" is sanitized. It is also possible to use a
regular expression instead, such as `*credentials.*` to sanitize any key that holds the
word `credentials` as part of the key.
The patterns to use can be customized using the `management.endpoint.env.keys-to-sanitize`
and `management.endpoint.configprops.keys-to-sanitize` respectively.
[[howto-security]]
== Security
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment