[client] Address review: redact and clear the MDM upload URL

- Never log the MDM-provided upload URL (it can embed credentials or
  signed query tokens): mark the key secret so it is redacted, and drop
  the raw value from the invalid-URL warning.
- Clear DebugBundleUploadURL when a replacement policy no longer carries
  the key, so a removed override can never keep directing uploads to a
  previously-enforced host; covered by a policy-replacement test.
- macOS docs: state "https URL with a host" consistently, and make the
  managed-plist helper fail closed on an invalid allowRemoteJobs value
  (emit false rather than dropping the key).
This commit is contained in:
mlsmaycon
2026-08-13 02:12:47 +09:00
committed by Maycon Santos
parent 90db57e3e5
commit c9568ba909
5 changed files with 27 additions and 8 deletions
+2
View File
@@ -82,6 +82,8 @@ const (
// SecretKeys lists keys whose values must be redacted in logs.
var SecretKeys = map[string]struct{}{
KeyPreSharedKey: {},
// The upload URL can embed credentials or signed query tokens.
KeyBundleUploadURL: {},
}
// boolStringLiterals enumerates the textual boolean encodings the