Hacker News new | ask | show | jobs
by serial_dev 438 days ago
Whether redacting the auth header is the best choice can be determined on a case by case basis, so I don't think it should redact by default. A big scary warning would definitely make sense, though!