fix: add missing credential fields to settings redaction lists (#11272)

* fix: redact Azure and AWS credential fields in instance settings

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix: redact the GitHub App private key in the settings change log

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ruben Fiszel
2026-09-21 23:36:24 +02:00
committed by GitHub
co-authored by Claude Opus 5
parent 965e8b0c23
commit 2a40f25bda
2 changed files with 24 additions and 3 deletions
+22 -1
View File
@@ -1029,9 +1029,10 @@ const NESTED_SENSITIVE_FIELDS: &[(&str, &[&str])] = &[
),
(
"object_store_cache_config",
&["secret_key", "serviceAccountKey"],
&["secret_key", "serviceAccountKey", "accessKey"],
),
("custom_instance_pg_databases", &["user_pwd"]),
("github_enterprise_app", &["private_key"]),
];
fn redact_json_value(value: &serde_json::Value) -> serde_json::Value {
@@ -2647,6 +2648,26 @@ mod tests {
assert!(formatted.contains("****"));
}
#[test]
fn format_setting_value_redacts_nested_credentials() {
let val = serde_json::json!({
"type": "Azure",
"accountName": "acct",
"containerName": "c",
"accessKey": "azure-storage-account-key-12345"
});
let formatted = format_setting_value("object_store_cache_config", &val);
assert!(!formatted.contains("azure-storage-account-key-12345"));
assert!(formatted.contains("acct"));
let val = serde_json::json!({
"app_id": 1,
"private_key": "-----BEGIN RSA PRIVATE KEY-----\nMIIEsecretbody\n-----END RSA PRIVATE KEY-----"
});
let formatted = format_setting_value("github_enterprise_app", &val);
assert!(!formatted.contains("MIIEsecretbody"));
}
#[test]
#[should_panic(expected = "literal_value() called on unresolved secret ref")]
fn string_or_secret_ref_literal_value_panics_on_ref() {
@@ -727,8 +727,8 @@
// Each entry maps a top-level key to its sensitive sub-field names.
const nestedSensitiveFields: Record<string, string[]> = {
smtp_settings: ['smtp_password'],
secret_backend: ['token'],
object_store_cache_config: ['secret_key', 'serviceAccountKey'],
secret_backend: ['token', 'client_secret', 'secret_access_key'],
object_store_cache_config: ['secret_key', 'serviceAccountKey', 'accessKey'],
custom_instance_pg_databases: ['user_pwd'],
rsa_keys: ['private_key'],
github_enterprise_app: ['private_key']