{"record":{"id":"9fff083121cb68dc","repo":"spring-projects/spring-ai","slug":"you-have-enabled-logging-out-the-chatclient-prompt","errorCode":null,"errorMessage":"You have enabled logging out the ChatClient prompt content with the risk of exposing sensitive or private information. Please, be careful!","messagePattern":"You have enabled logging out the ChatClient prompt content with the risk of exposing sensitive or private information\\. Please, be careful!","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"auto-configurations/models/chat/client/spring-ai-autoconfigure-model-chat-client/src/main/java/org/springframework/ai/model/chat/client/autoconfigure/ChatClientAutoConfiguration.java","lineNumber":77,"sourceCode":" * @author Christian Tzolov\n * @author Mark Pollack\n * @author Josh Long\n * @author Arjen Poutsma\n * @author Thomas Vitale\n * @author Jonatan Ivanov\n * @since 1.0.0\n */\n@AutoConfiguration(after = ToolCallingAutoConfiguration.class)\n@ConditionalOnClass(ChatClient.class)\n@EnableConfigurationProperties(ChatClientBuilderProperties.class)\n@ConditionalOnProperty(prefix = ChatClientBuilderProperties.CONFIG_PREFIX, name = \"enabled\", havingValue = \"true\",\n\t\tmatchIfMissing = true)\npublic class ChatClientAutoConfiguration {\n\n\tprivate static final Log logger = LogFactory.getLog(ChatClientAutoConfiguration.class);\n\n\tprivate static void logPromptContentWarning() {\n\t\tlogger.warn(\n\t\t\t\t\"You have enabled logging out the ChatClient prompt content with the risk of exposing sensitive or private information. Please, be careful!\");\n\t}\n\n\tprivate static void logCompletionWarning() {\n\t\tlogger.warn(\n\t\t\t\t\"You have enabled logging out the ChatClient completion content with the risk of exposing sensitive or private information. Please, be careful!\");\n\t}\n\n\t@Bean\n\t@ConditionalOnMissingBean\n\t@SuppressWarnings(\"removal\")\n\tChatClientBuilderConfigurer chatClientBuilderConfigurer(ObjectProvider<ChatClientCustomizer> customizerProvider,\n\t\t\tObjectProvider<ChatClientBuilderCustomizer> builderCustomizerProvider) {\n\t\tChatClientBuilderConfigurer configurer = new ChatClientBuilderConfigurer();\n\t\tconfigurer.setChatClientCustomizers(customizerProvider.orderedStream().toList());\n\t\tconfigurer.setChatClientBuilderCustomizers(builderCustomizerProvider.orderedStream().toList());\n\t\treturn configurer;\n\t}","sourceCodeStart":59,"sourceCodeEnd":95,"githubUrl":"https://github.com/spring-projects/spring-ai/blob/98a7beda4f29d80a71c5837eb4053b03a93a46f7/auto-configurations/models/chat/client/spring-ai-autoconfigure-model-chat-client/src/main/java/org/springframework/ai/model/chat/client/autoconfigure/ChatClientAutoConfiguration.java#L59-L95","documentation":"ChatClientAutoConfiguration.logPromptContentWarning emits this warning when prompt content observability logging is enabled for the ChatClient builder. Logging full prompts can leak sensitive or private data into logs, so the library warns explicitly whenever the property opts you into it.","triggerScenarios":"Setting the spring.ai.chat.client prompt-content logging property (e.g. spring.ai.chat.client.observation.log-prompt-content=true, default matchIfMissing variant aside) so the conditional bean method runs at auto-configuration time.","commonSituations":"Enabling prompt logging for local debugging and shipping the config to production; copying example configs that enable observation logging; compliance scans flagging PII in logs after enabling this property.","solutions":["Disable the property in production (spring.ai.chat.client...log-prompt-content=false).","Keep it enabled only in dev/test profiles via profile-scoped configuration.","If prompts must be logged, route logs to a redacting/secure logging pipeline."],"exampleFix":"// before (application.yml)\nspring.ai.chat.client.observation.log-prompt-content: true\n// after\nspring.ai.chat.client.observation.log-prompt-content: false","handlingStrategy":"validation","validationCode":"boolean loggingPrompts = env.getProperty(\n    \"spring.ai.chat.client.observation.log-prompt-content\", Boolean.class, false);\nif (loggingPrompts && isProduction) {\n    throw new IllegalStateException(\"Prompt content logging must be disabled in production\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep content-logging flags off in production profiles.","Add a startup check that fails prod deploys when sensitive logging is on.","Audit logs regularly for leaked prompt data."],"tags":["logging","security","privacy","chat-client","observation"],"backgroundTag":"sensitive-data-logging","analyzedSha":"98a7beda4f29d80a71c5837eb4053b03a93a46f7","analyzedAt":"2026-09-11T14:15:49.441Z","contentChangedAt":"2026-09-11T14:15:49.441Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}