spring-projects/spring-ai · warning

You have enabled logging out of the query response content…

Error message

You have enabled logging out of the query response content with the risk of exposing sensitive or private information. Please, be careful!

What it means

Startup warning from Spring AI's vector store observation auto-configuration. Enabling spring.ai.vectorstore.observations.include-query-response=true logs query response content (retrieved documents) in observations, which risks exposing private data stored in the vector store. The warning is emitted once when logQueryResponseContentWarning() runs during bean setup.

Solutions

  1. Set spring.ai.vectorstore.observations.include-query-response=false in production configuration.
  2. Enable the flag only under a non-production Spring profile.
  3. Restrict access to the tracing backend and apply retention/scrubbing policies if enabled.
  4. Silence the logger for VectorStoreObservationAutoConfiguration if the warning is intentionally accepted.

Example fix

// before (application.yml)
spring:
  ai:
    vectorstore:
      observations:
        include-query-response: true
// after
spring:
  ai:
    vectorstore:
      observations:
        include-query-response: false  # enable only in dev
Defensive patterns

Strategy: validation

Validate before calling

boolean risky = env.getProperty("spring.ai.vectorstore.observations.include-query-response", Boolean.class, false);
if (risky && isProductionProfile(env)) {
    throw new IllegalStateException("vector store query response logging must be off in production");
}

Prevention

When it happens

Trigger: Setting spring.ai.vectorstore.observations.include-query-response=true while the vector store observation auto-configuration is active.

Common situations: Debugging RAG retrieval quality and leaving response logging on in production; vector stores containing customer documents whose text is then shipped to tracing backends; teams unaware that retrieved chunks appear in traces.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-ai@98a7beda4f (2026-09-11). Data as JSON: /api/errors/da1aa186a5f8d877. Report an issue: GitHub.

Appendix: source

Thrown at auto-configurations/vector-stores/spring-ai-autoconfigure-vector-store-observation/src/main/java/org/springframework/ai/vectorstore/observation/autoconfigure/VectorStoreObservationAutoConfiguration.java:53

import org.springframework.context.annotation.Configuration;

/**
 * Auto-configuration for Spring AI vector store observations.
 *
 * @author Christian Tzolov
 * @author Thomas Vitale
 * @author Jonatan Ivanov
 * @since 1.0.0
 */
@AutoConfiguration
@ConditionalOnClass(VectorStore.class)
@EnableConfigurationProperties(VectorStoreObservationProperties.class)
public class VectorStoreObservationAutoConfiguration {

	private static final Log logger = LogFactory.getLog(VectorStoreObservationAutoConfiguration.class);

	private static void logQueryResponseContentWarning() {
		logger.warn(
				"You have enabled logging out of the query response content with the risk of exposing sensitive or private information. Please, be careful!");
	}

	@Configuration(proxyBeanMethods = false)
	@ConditionalOnClass(Tracer.class)
	@ConditionalOnBean(Tracer.class)
	static class TracerPresentObservationConfiguration {

		@Bean
		@ConditionalOnMissingBean(value = VectorStoreQueryResponseObservationHandler.class,
				name = "vectorStoreQueryResponseObservationHandler")
		@ConditionalOnProperty(prefix = VectorStoreObservationProperties.CONFIG_PREFIX, name = "log-query-response",
				havingValue = "true")
		TracingAwareLoggingObservationHandler<VectorStoreObservationContext> vectorStoreQueryResponseObservationHandler(
				Tracer tracer) {
			logQueryResponseContentWarning();
			return new TracingAwareLoggingObservationHandler<>(new VectorStoreQueryResponseObservationHandler(),
					tracer);

View on GitHub (pinned to 98a7beda4f)