Launcher logs login.live.com and sisu.xboxlive.com URLs
The bug
When signing in with a Microsoft account the launcher logs login.live.com and sisu.xboxlive.com URLs in the launcher_log.txt. Those URLs seem to contain potentially sensitive information in the URL query parameters.
Is this information sensitive? If so it would be good to not log that because users frequently share the launcher_log.txt file publicly for troubleshooting.
Might also affect xsts.auth.xboxlive.com/xsts/authorize, see MCL-22008.
Reproduction steps
- Click "Add Microsoft account" in the launcher (also seems to work if you have already added your Microsoft account)
- After completing the authentication open the launcher_log.txt file and search for "https://login.live.com" and "https://sisu.xboxlive.com"
2022-07-18, 12:59 AM
2023-10-03, 06:53 PM
2023-10-03, 05:58 PM
0
5
855232
2.3.280 (Windows), 2.3.280 (Mac), 2.3.324 (Windows)
-