{"record":{"id":"1039f6730a60443e","repo":"spring-projects/spring-ai","slug":"you-have-enabled-logging-out-the-image-prompt-cont","errorCode":null,"errorMessage":"You have enabled logging out the image prompt content with the risk of exposing sensitive or private information. Please, be careful!","messagePattern":"You have enabled logging out the image prompt content with the risk of exposing sensitive or private information\\. Please, be careful!","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"auto-configurations/models/image/observation/spring-ai-autoconfigure-model-image-observation/src/main/java/org/springframework/ai/model/image/observation/autoconfigure/ImageObservationAutoConfiguration.java","lineNumber":52,"sourceCode":"import org.springframework.context.annotation.Bean;\nimport org.springframework.context.annotation.Configuration;\n\n/**\n * Auto-configuration for Spring AI image model observations.\n *\n * @author Thomas Vitale\n * @author Jonatan Ivanov\n * @since 1.0.0\n */\n@AutoConfiguration\n@ConditionalOnClass(ImageModel.class)\n@EnableConfigurationProperties(ImageObservationProperties.class)\npublic class ImageObservationAutoConfiguration {\n\n\tprivate static final Log logger = LogFactory.getLog(ImageObservationAutoConfiguration.class);\n\n\tprivate static void logPromptContentWarning() {\n\t\tlogger.warn(\n\t\t\t\t\"You have enabled logging out the image prompt content with the risk of exposing sensitive or private information. Please, be careful!\");\n\t}\n\n\t@Configuration(proxyBeanMethods = false)\n\t@ConditionalOnClass(Tracer.class)\n\t@ConditionalOnBean(Tracer.class)\n\tstatic class TracerPresentObservationConfiguration {\n\n\t\t@Bean\n\t\t@ConditionalOnMissingBean(value = ImageModelPromptContentObservationHandler.class,\n\t\t\t\tname = \"imageModelPromptContentObservationHandler\")\n\t\t@ConditionalOnProperty(prefix = ImageObservationProperties.CONFIG_PREFIX, name = \"log-prompt\",\n\t\t\t\thavingValue = \"true\")\n\t\tTracingAwareLoggingObservationHandler<ImageModelObservationContext> imageModelPromptContentObservationHandler(\n\t\t\t\tTracer tracer) {\n\t\t\tlogPromptContentWarning();\n\t\t\treturn new TracingAwareLoggingObservationHandler<>(new ImageModelPromptContentObservationHandler(), tracer);\n\t\t}","sourceCodeStart":34,"sourceCodeEnd":70,"githubUrl":"https://github.com/spring-projects/spring-ai/blob/98a7beda4f29d80a71c5837eb4053b03a93a46f7/auto-configurations/models/image/observation/spring-ai-autoconfigure-model-image-observation/src/main/java/org/springframework/ai/model/image/observation/autoconfigure/ImageObservationAutoConfiguration.java#L34-L70","documentation":"A startup warning from Spring AI's image observation auto-configuration. Enabling spring.ai.image.observations.include-prompt=true causes image generation prompt content to be recorded in observations, risking exposure of sensitive or private information. The warning is logged once so the operator is aware of the trade-off.","triggerScenarios":"Setting spring.ai.image.observations.include-prompt=true (ImageObservationProperties.includePrompt) while the image observation auto-configuration beans are created, triggering logPromptContentWarning().","commonSituations":"Debugging image-model prompts in development and leaving the flag enabled when deploying; organizations with strict data-handling rules where prompt text must not leave the application; shared tracing backends where image prompts become visible to a wider audience.","solutions":["Set spring.ai.image.observations.include-prompt=false in production configuration.","Enable the flag only in a dev/test Spring profile so production does not inherit it.","If the warning is accepted, silence the logger for ImageObservationAutoConfiguration in your logging config.","Review who can access your tracing backend and add data-scrubbing if prompts must be recorded."],"exampleFix":"// before (application.yml)\nspring:\n  ai:\n    image:\n      observations:\n        include-prompt: true\n// after\nspring:\n  ai:\n    image:\n      observations:\n        include-prompt: false  # enable only in dev profile","handlingStrategy":"validation","validationCode":"boolean risky = env.getProperty(\"spring.ai.image.observations.include-prompt\", Boolean.class, false);\nif (risky && isProductionProfile(env)) {\n    throw new IllegalStateException(\"image prompt logging must be disabled in production\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Review image observation properties per environment during release checklists.","Centralize observability flags in one profile-specific file to ease review.","Ensure tracing backends enforce access control and retention limits.","Document accepted-risk decisions when the flag stays enabled."],"tags":["observability","privacy","logging","spring-ai"],"backgroundTag":"invalid-config-value","analyzedSha":"98a7beda4f29d80a71c5837eb4053b03a93a46f7","analyzedAt":"2026-09-11T14:15:49.441Z","contentChangedAt":"2026-09-11T14:15:49.441Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}