{"record":{"id":"da1aa186a5f8d877","repo":"spring-projects/spring-ai","slug":"you-have-enabled-logging-out-of-the-query-response","errorCode":null,"errorMessage":"You have enabled logging out of the query response content with the risk of exposing sensitive or private information. Please, be careful!","messagePattern":"You have enabled logging out of the query response content with the risk of exposing sensitive or private information\\. Please, be careful!","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"auto-configurations/vector-stores/spring-ai-autoconfigure-vector-store-observation/src/main/java/org/springframework/ai/vectorstore/observation/autoconfigure/VectorStoreObservationAutoConfiguration.java","lineNumber":53,"sourceCode":"import org.springframework.context.annotation.Configuration;\n\n/**\n * Auto-configuration for Spring AI vector store observations.\n *\n * @author Christian Tzolov\n * @author Thomas Vitale\n * @author Jonatan Ivanov\n * @since 1.0.0\n */\n@AutoConfiguration\n@ConditionalOnClass(VectorStore.class)\n@EnableConfigurationProperties(VectorStoreObservationProperties.class)\npublic class VectorStoreObservationAutoConfiguration {\n\n\tprivate static final Log logger = LogFactory.getLog(VectorStoreObservationAutoConfiguration.class);\n\n\tprivate static void logQueryResponseContentWarning() {\n\t\tlogger.warn(\n\t\t\t\t\"You have enabled logging out of the query response content with the risk of exposing sensitive or private information. Please, be careful!\");\n\t}\n\n\t@Configuration(proxyBeanMethods = false)\n\t@ConditionalOnClass(Tracer.class)\n\t@ConditionalOnBean(Tracer.class)\n\tstatic class TracerPresentObservationConfiguration {\n\n\t\t@Bean\n\t\t@ConditionalOnMissingBean(value = VectorStoreQueryResponseObservationHandler.class,\n\t\t\t\tname = \"vectorStoreQueryResponseObservationHandler\")\n\t\t@ConditionalOnProperty(prefix = VectorStoreObservationProperties.CONFIG_PREFIX, name = \"log-query-response\",\n\t\t\t\thavingValue = \"true\")\n\t\tTracingAwareLoggingObservationHandler<VectorStoreObservationContext> vectorStoreQueryResponseObservationHandler(\n\t\t\t\tTracer tracer) {\n\t\t\tlogQueryResponseContentWarning();\n\t\t\treturn new TracingAwareLoggingObservationHandler<>(new VectorStoreQueryResponseObservationHandler(),\n\t\t\t\t\ttracer);","sourceCodeStart":35,"sourceCodeEnd":71,"githubUrl":"https://github.com/spring-projects/spring-ai/blob/98a7beda4f29d80a71c5837eb4053b03a93a46f7/auto-configurations/vector-stores/spring-ai-autoconfigure-vector-store-observation/src/main/java/org/springframework/ai/vectorstore/observation/autoconfigure/VectorStoreObservationAutoConfiguration.java#L35-L71","documentation":"Startup warning from Spring AI's vector store observation auto-configuration. Enabling spring.ai.vectorstore.observations.include-query-response=true logs query response content (retrieved documents) in observations, which risks exposing private data stored in the vector store. The warning is emitted once when logQueryResponseContentWarning() runs during bean setup.","triggerScenarios":"Setting spring.ai.vectorstore.observations.include-query-response=true while the vector store observation auto-configuration is active.","commonSituations":"Debugging RAG retrieval quality and leaving response logging on in production; vector stores containing customer documents whose text is then shipped to tracing backends; teams unaware that retrieved chunks appear in traces.","solutions":["Set spring.ai.vectorstore.observations.include-query-response=false in production configuration.","Enable the flag only under a non-production Spring profile.","Restrict access to the tracing backend and apply retention/scrubbing policies if enabled.","Silence the logger for VectorStoreObservationAutoConfiguration if the warning is intentionally accepted."],"exampleFix":"// before (application.yml)\nspring:\n  ai:\n    vectorstore:\n      observations:\n        include-query-response: true\n// after\nspring:\n  ai:\n    vectorstore:\n      observations:\n        include-query-response: false  # enable only in dev","handlingStrategy":"validation","validationCode":"boolean risky = env.getProperty(\"spring.ai.vectorstore.observations.include-query-response\", Boolean.class, false);\nif (risky && isProductionProfile(env)) {\n    throw new IllegalStateException(\"vector store query response logging must be off in production\");\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Remember retrieved documents are user/private content — never log them by default.","Gate the flag behind a dev profile and review diffs to prod config.","Restrict who can query the tracing backend.","Periodically audit active observation filters registered in the application context."],"tags":["observability","privacy","vector-store","rag"],"backgroundTag":"invalid-config-value","analyzedSha":"98a7beda4f29d80a71c5837eb4053b03a93a46f7","analyzedAt":"2026-09-11T14:15:49.441Z","contentChangedAt":"2026-09-11T14:15:49.441Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}