The /actuator/env Sanitizer Doesn't Know Your Naming Conventions
Spring Boot's default sanitizer masks password, secret, and token. But if your team names things differently, /actuator/env shows them in plain text. Here's the criterion for closing that gap without killing the endpoint.
Sep 11 2026 · 7′ · Tutorials · spring-boot · java