| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -540,8 +540,7 @@ def expand_path(p: Union[None, PathLike], expand_vars: bool = True) -> Optional[ | |||
| 540 | 540 | ||
| 541 | 541 | ||
| 542 | 542 | def remove_password_if_present(cmdline: Sequence[str]) -> List[str]: | |
| 543 | - """Parse any command line argument and if one of the elements is an URL with a | ||
| 544 | - username and/or password, replace them by stars (in-place). | ||
| 543 | + """Redact credentials in URLs and HTTP Authorization extra headers in a command line. | ||
| 545 | 544 | ||
| 546 | 545 | If nothing is found, this just returns the command line as-is. | |
| 547 | 546 | ||
@@ -551,6 +550,16 @@ def remove_password_if_present(cmdline: Sequence[str]) -> List[str]: | |||
| 551 | 550 | new_cmdline = [] | |
| 552 | 551 | for index, to_parse in enumerate(cmdline): | |
| 553 | 552 | new_cmdline.append(to_parse) | |
| 553 | + config_key, separator, header = to_parse.partition("=") | ||
| 554 | + header_name, colon, _ = header.partition(":") | ||
| 555 | + if ( | ||
| 556 | + separator | ||
| 557 | + and colon | ||
| 558 | + and config_key.lower().endswith(".extraheader") | ||
| 559 | + and header_name.strip().lower() == "authorization" | ||
| 560 | + ): | ||
| 561 | + new_cmdline[index] = "%s%s%s%s *****" % (config_key, separator, header_name, colon) | ||
| 562 | + continue | ||
| 554 | 563 | try: | |
| 555 | 564 | url = urlsplit(to_parse) | |
| 556 | 565 | # Remove password from the URL if present. | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -395,6 +395,24 @@ def test_it_raises_proper_exception_with_output_stream(self): | |||
| 395 | 395 | with self.assertRaises(GitCommandError): | |
| 396 | 396 | self.git.checkout("non-existent-branch", output_stream=tmp_file) | |
| 397 | 397 | ||
| 398 | + def test_it_redacts_authorization_extra_header_from_error(self): | ||
| 399 | + token = "fake-token-1234" | ||
| 400 | + command = [ | ||
| 401 | + "git", | ||
| 402 | + "-c", | ||
| 403 | + "http.extraHeader=Authorization: Bearer %s" % token, | ||
| 404 | + "rev-parse", | ||
| 405 | + "--verify", | ||
| 406 | + "refs/does-not-exist", | ||
| 407 | + ] | ||
| 408 | + | ||
| 409 | + with self.assertRaises(GitCommandError) as context: | ||
| 410 | + self.git.execute(command) | ||
| 411 | + | ||
| 412 | + message = str(context.exception) | ||
| 413 | + self.assertNotIn(token, message) | ||
| 414 | + self.assertIn("http.extraHeader=Authorization: *****", message) | ||
| 415 | + | ||
| 398 | 416 | def test_it_accepts_environment_variables(self): | |
| 399 | 417 | filename = fixture_path("ls_tree_empty") | |
| 400 | 418 | with open(filename, "r") as fh: | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -671,6 +671,7 @@ def test_pickle_tzoffset(self): | |||
| 671 | 671 | def test_remove_password_from_command_line(self): | |
| 672 | 672 | username = "fakeuser" | |
| 673 | 673 | password = "fakepassword1234" | |
| 674 | + authorization = "Bearer fake-token-1234" | ||
| 674 | 675 | url_with_user_and_pass = "https://{}:{}@fakerepo.example.com/testrepo".format(username, password) | |
| 675 | 676 | url_with_user = "https://{}@fakerepo.example.com/testrepo".format(username) | |
| 676 | 677 | url_with_pass = "https://:{}@fakerepo.example.com/testrepo".format(password) | |
@@ -681,6 +682,7 @@ def test_remove_password_from_command_line(self): | |||
| 681 | 682 | cmd_3 = ["git", "clone", "-v", url_with_pass] | |
| 682 | 683 | cmd_4 = ["git", "clone", "-v", url_without_user_or_pass] | |
| 683 | 684 | cmd_5 = ["no", "url", "in", "this", "one"] | |
| 685 | + cmd_6 = ["git", "-c", "http.extraHeader=Authorization: %s" % authorization, "fetch"] | ||
| 684 | 686 | ||
| 685 | 687 | redacted_cmd_1 = remove_password_if_present(cmd_1) | |
| 686 | 688 | assert username not in " ".join(redacted_cmd_1) | |
@@ -700,3 +702,7 @@ def test_remove_password_from_command_line(self): | |||
| 700 | 702 | ||
| 701 | 703 | assert cmd_4 == remove_password_if_present(cmd_4) | |
| 702 | 704 | assert cmd_5 == remove_password_if_present(cmd_5) | |
| 705 | + | ||
| 706 | + redacted_cmd_6 = remove_password_if_present(cmd_6) | ||
| 707 | + assert authorization not in " ".join(redacted_cmd_6) | ||
| 708 | + assert "http.extraHeader=Authorization: *****" in redacted_cmd_6 | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments