Don't log query strings
gitlab-pages logs full HTTP request URIs in a number of places. IT has no tokens or authorization of its own (at present), but users may place JS on Pages that requires the page to be accessed with credentials in the query string.
The behaviour of gitlab-pages is completely unaffected by the query-string of an URL, so to be safe, we can simply omit the query string from every URL we log.