There's already a strategy to remove AUTH and ACL SETUSER from the redis.cli log in redis-cli.c but I think there may be an opportunity here to also remove config set requirepass as well and to mark this as dangerous

This would help ensure that someone who does not use a redis.conf file or is manually changing the password for backward compatibility with ACLs is able to find this command in the log if it's done on a remote host/workstation and the server is configured with AUTH for backwards compatibility.

@antirez @yossigo @itamarhaber - what are your thoughts?

Comment From: yossigo

@IAmATeaPot418 While at it, I believe CONFIG SET masterauth and CONFIG SET masteruser should be masked as well.

Comment From: itamarhaber

@yossigo agreed, added to #7082

Comment From: IAmATeaPot418

@yossigo @itamarhaber - What about Migrate too now that we are on the subject ;) ?

Comment From: huangzhw

Fixed by https://github.com/redis/redis/pull/8895