メインコンテンツまでスキップ
このページはまだお使いの言語に翻訳されていないか、翻訳が技術レビュー待ちです。以下には英語の原文を表示しています。 英語のページを開く

E1709. Secret value leak in payload

Severity: ERROR. Class: SecretValueLeakInPayload (subclass of RuntimeError).

What happened​

An audit row or telemetry event for a Secrets:* action carried a field whose shape matches a credential value. The SDK rejected the payload pre-send; the backend's CHECK constraint would have rejected it anyway.

Why it matters​

Three-layer redaction guarantees secret values NEVER reach disk / network / telemetry. This error fires when the guarantee is challenged.

How to fix​

Find the leak source. Most likely a custom audit hook or telemetry middleware that didn't redact. Audit your code with controlzero doctor --redaction. The SDK ships with a value-shape regex covering sk-*, xoxb-*, AKIA*, ghp_*, and similar patterns.

Catching this error​

except RuntimeError catches this. Programmer error.

See also​