Remove unused, sensitive data.
HEAD mainWe were not using this data, stored in the session. It is sensitive
data, therefore, we avoid collecting it in the first place.
1 files changed, 0 insertions, 5 deletions
diff --git a/uploader/session.py b/uploader/session.py
index 9cb305b..1dcf8ac 100644
--- a/uploader/session.py
+++ b/uploader/session.py
@@ -25,8 +25,6 @@ class SessionInfo(TypedDict):
session_id: UUID
user: UserDetails
anon_id: UUID
- user_agent: str
- ip_addr: str
masquerade: Optional[UserDetails]
auth_server_jwks: Optional[dict[str, Any]]
@@ -69,9 +67,6 @@ def session_info() -> SessionInfo:
"logged_in": False
},
"anon_id": anon_id,
- "user_agent": request.headers.get("User-Agent"),
- "ip_addr": request.environ.get("HTTP_X_FORWARDED_FOR",
- request.remote_addr),
"masquerading": None
}))
|