feat: anonymize IPs via HMAC before persisting to MongoDB
GDPR compliance — IPs are HMAC-SHA256'd (truncated to 16 hex chars) before being pushed to the Redis queue, so only pseudonymous tokens are ever stored. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -8,7 +8,7 @@ export default defineEventHandler((event) => {
|
||||
|
||||
event.node.res.on("finish", () => {
|
||||
logRequest({
|
||||
ip,
|
||||
ip: anonymizeIp(ip),
|
||||
path,
|
||||
method,
|
||||
statusCode: event.node.res.statusCode,
|
||||
|
||||
Reference in New Issue
Block a user