{"version":"2.1.285","anchor":"log-redaction-strips-extra-userinfo-from-urls","canonical_anchor":"log-redaction-strips-extra-userinfo-from-urls","heading":"Login details inside URLs are more thoroughly hidden in logs","tier":"notice","area":"Redaction","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/log-redaction-strips-extra-userinfo-from-urls","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Login details inside URLs are more thoroughly hidden in logs\n\nLogs now mask usernames and passwords in URLs as ***:***@ and also strip any extra @-separated parts that follow\n\n**What**\n\nSome web addresses carry a username and password before the host, for example `https:\/\/user:pass@host`. When Claude Code writes logs, it now masks that part as `***:***@`, and also removes any further `@`-separated pieces that follow it. That way a password containing an `@` cannot leave part of itself behind.\n\n**Why**\n\nThis keeps credentials that appear in URLs from leaking into log files.\n\n- Area: Redaction\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}