spring-projects/spring-ai · warning

You have enabled logging out the ChatClient prompt content…

Error message

You have enabled logging out the ChatClient prompt content with the risk of exposing sensitive or private information. Please, be careful!

What it means

ChatClientAutoConfiguration.logPromptContentWarning emits this warning when prompt content observability logging is enabled for the ChatClient builder. Logging full prompts can leak sensitive or private data into logs, so the library warns explicitly whenever the property opts you into it.

Solutions

  1. Disable the property in production (spring.ai.chat.client...log-prompt-content=false).
  2. Keep it enabled only in dev/test profiles via profile-scoped configuration.
  3. If prompts must be logged, route logs to a redacting/secure logging pipeline.

Example fix

// before (application.yml)
spring.ai.chat.client.observation.log-prompt-content: true
// after
spring.ai.chat.client.observation.log-prompt-content: false
Defensive patterns

Strategy: validation

Validate before calling

boolean loggingPrompts = env.getProperty(
    "spring.ai.chat.client.observation.log-prompt-content", Boolean.class, false);
if (loggingPrompts && isProduction) {
    throw new IllegalStateException("Prompt content logging must be disabled in production");
}

Prevention

When it happens

Trigger: Setting the spring.ai.chat.client prompt-content logging property (e.g. spring.ai.chat.client.observation.log-prompt-content=true, default matchIfMissing variant aside) so the conditional bean method runs at auto-configuration time.

Common situations: Enabling prompt logging for local debugging and shipping the config to production; copying example configs that enable observation logging; compliance scans flagging PII in logs after enabling this property.

Related errors


AI-assisted analysis of spring-projects/spring-ai@98a7beda4f (2026-09-11). Data as JSON: /api/errors/9fff083121cb68dc. Report an issue: GitHub.

Appendix: source

Thrown at auto-configurations/models/chat/client/spring-ai-autoconfigure-model-chat-client/src/main/java/org/springframework/ai/model/chat/client/autoconfigure/ChatClientAutoConfiguration.java:77

 * @author Christian Tzolov
 * @author Mark Pollack
 * @author Josh Long
 * @author Arjen Poutsma
 * @author Thomas Vitale
 * @author Jonatan Ivanov
 * @since 1.0.0
 */
@AutoConfiguration(after = ToolCallingAutoConfiguration.class)
@ConditionalOnClass(ChatClient.class)
@EnableConfigurationProperties(ChatClientBuilderProperties.class)
@ConditionalOnProperty(prefix = ChatClientBuilderProperties.CONFIG_PREFIX, name = "enabled", havingValue = "true",
		matchIfMissing = true)
public class ChatClientAutoConfiguration {

	private static final Log logger = LogFactory.getLog(ChatClientAutoConfiguration.class);

	private static void logPromptContentWarning() {
		logger.warn(
				"You have enabled logging out the ChatClient prompt content with the risk of exposing sensitive or private information. Please, be careful!");
	}

	private static void logCompletionWarning() {
		logger.warn(
				"You have enabled logging out the ChatClient completion content with the risk of exposing sensitive or private information. Please, be careful!");
	}

	@Bean
	@ConditionalOnMissingBean
	@SuppressWarnings("removal")
	ChatClientBuilderConfigurer chatClientBuilderConfigurer(ObjectProvider<ChatClientCustomizer> customizerProvider,
			ObjectProvider<ChatClientBuilderCustomizer> builderCustomizerProvider) {
		ChatClientBuilderConfigurer configurer = new ChatClientBuilderConfigurer();
		configurer.setChatClientCustomizers(customizerProvider.orderedStream().toList());
		configurer.setChatClientBuilderCustomizers(builderCustomizerProvider.orderedStream().toList());
		return configurer;
	}

View on GitHub (pinned to 98a7beda4f)