#37398 closed Bug (wontfix)

SafeExceptionReporterFilter does not cleanse settings named *_CREDENTIALS / CREDENTIAL

Reported by: venkatchalla06 Owned by:
Component: Error reporting Version: dev
Severity: Normal Keywords:
Cc: venkatchalla06 Triage Stage: Unreviewed
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

SafeExceptionReporterFilter.hidden_settings (django/views/debug.py) redacts settings whose name matches the regex API|AUTH|TOKEN|KEY|SECRET|PASS|SIGNATURE|HTTP_COOKIE.

A flat setting whose name contains only CREDENTIAL(S) — for example GOOGLE_APPLICATION_CREDENTIALS or a project's own <SERVICE>_CREDENTIALS — is not matched, so its value is shown in the clear on the technical 500 page and in AdminEmailHandler error emails.

AWS_SECRET_ACCESS_KEY is already covered (via SECRET/KEY), so this only affects settings coined with the word "credential", but that is a common naming convention for service-account and database credential settings.

Proposed fix: add CREDENTIAL to the hidden_settings regex. Direct precedent: #35646 added AUTH and HTTP_COOKIE to this same list.

I have a patch (code + docs + tests) ready to submit once this ticket is triaged.

Change History (1)

comment:1 by Sarah Boyce, 28 minutes ago

Resolution: → wontfix
Status: new → closed

I think we need a solid example of a common Django package defining a setting which would then be rendered exposing a secret.
Folks can use the existing naming convention when defining their own settings. I don't think we should just keep increasing the list for every possible scenario

Note: See TracTickets for help on using tickets.
Back to Top