mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-03 08:02:19 +00:00
fix: add missing credential fields to settings redaction lists (#11272)
* fix: redact Azure and AWS credential fields in instance settings Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix: redact the GitHub App private key in the settings change log Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
965e8b0c23
commit
2a40f25bda
@@ -1029,9 +1029,10 @@ const NESTED_SENSITIVE_FIELDS: &[(&str, &[&str])] = &[
|
||||
),
|
||||
(
|
||||
"object_store_cache_config",
|
||||
&["secret_key", "serviceAccountKey"],
|
||||
&["secret_key", "serviceAccountKey", "accessKey"],
|
||||
),
|
||||
("custom_instance_pg_databases", &["user_pwd"]),
|
||||
("github_enterprise_app", &["private_key"]),
|
||||
];
|
||||
|
||||
fn redact_json_value(value: &serde_json::Value) -> serde_json::Value {
|
||||
@@ -2647,6 +2648,26 @@ mod tests {
|
||||
assert!(formatted.contains("****"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn format_setting_value_redacts_nested_credentials() {
|
||||
let val = serde_json::json!({
|
||||
"type": "Azure",
|
||||
"accountName": "acct",
|
||||
"containerName": "c",
|
||||
"accessKey": "azure-storage-account-key-12345"
|
||||
});
|
||||
let formatted = format_setting_value("object_store_cache_config", &val);
|
||||
assert!(!formatted.contains("azure-storage-account-key-12345"));
|
||||
assert!(formatted.contains("acct"));
|
||||
|
||||
let val = serde_json::json!({
|
||||
"app_id": 1,
|
||||
"private_key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEsecretbody\n-----END RSA PRIVATE KEY-----"
|
||||
});
|
||||
let formatted = format_setting_value("github_enterprise_app", &val);
|
||||
assert!(!formatted.contains("MIIEsecretbody"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
#[should_panic(expected = "literal_value() called on unresolved secret ref")]
|
||||
fn string_or_secret_ref_literal_value_panics_on_ref() {
|
||||
|
||||
@@ -727,8 +727,8 @@
|
||||
// Each entry maps a top-level key to its sensitive sub-field names.
|
||||
const nestedSensitiveFields: Record<string, string[]> = {
|
||||
smtp_settings: ['smtp_password'],
|
||||
secret_backend: ['token'],
|
||||
object_store_cache_config: ['secret_key', 'serviceAccountKey'],
|
||||
secret_backend: ['token', 'client_secret', 'secret_access_key'],
|
||||
object_store_cache_config: ['secret_key', 'serviceAccountKey', 'accessKey'],
|
||||
custom_instance_pg_databases: ['user_pwd'],
|
||||
rsa_keys: ['private_key'],
|
||||
github_enterprise_app: ['private_key']
|
||||
|
||||
Reference in New Issue
Block a user