[fix] solution/backend: DB 엔진 생성 로그에서 비밀번호 제거 — 호스트·포트·DB 이름만 남긴다

백엔드가 뜰 때마다 접속 주소 전체(아이디·비밀번호 포함)를 INFO 로그에 찍고 있었다.
컨테이너 로그를 볼 수 있는 사람이면 누구나 운영 DB 비밀번호를 읽을 수 있었다.

- db_session_manager.create_engine: 읽기·쓰기 로그를 host:port/name 으로

py_compile 통과

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Mina Choi 2026-09-30 14:07:40 +09:00
parent e6a46154b1
commit 2985557838

View File

@ -46,11 +46,11 @@ class DBSessionManager(Singleton):
if db_wr_type == DBWRType.DB_READ.value: if db_wr_type == DBWRType.DB_READ.value:
pw = (":" + db_config.read_pw) if len(db_config.read_pw) > 0 else "" pw = (":" + db_config.read_pw) if len(db_config.read_pw) > 0 else ""
db_url = f"{self.__DB_URL_MAP[db_config.db_type]}://{db_config.read_id}{pw}@{db_config.read_host}:{db_config.read_port}/{db_config.name}" db_url = f"{self.__DB_URL_MAP[db_config.db_type]}://{db_config.read_id}{pw}@{db_config.read_host}:{db_config.read_port}/{db_config.name}"
LOG.i(f"Read DB create engine url : {db_url}") LOG.i(f"Read DB create engine : {db_config.read_host}:{db_config.read_port}/{db_config.name}")
else: else:
pw = (":" + db_config.write_pw) if len(db_config.write_pw) > 0 else "" pw = (":" + db_config.write_pw) if len(db_config.write_pw) > 0 else ""
db_url = f"{self.__DB_URL_MAP[db_config.db_type]}://{db_config.write_id}{pw}@{db_config.write_host}:{db_config.write_port}/{db_config.name}" db_url = f"{self.__DB_URL_MAP[db_config.db_type]}://{db_config.write_id}{pw}@{db_config.write_host}:{db_config.write_port}/{db_config.name}"
LOG.i(f"Write DB create engine url : {db_url}") LOG.i(f"Write DB create engine : {db_config.write_host}:{db_config.write_port}/{db_config.name}")
# SSL/TLS: 관리형 DB(RDS/Aurora/Azure)는 보통 TLS 필수. # SSL/TLS: 관리형 DB(RDS/Aurora/Azure)는 보통 TLS 필수.
connect_args = {} connect_args = {}