Opened 70 minutes ago
Closed 28 minutes ago
#37398 closed Bug (wontfix)
SafeExceptionReporterFilter does not cleanse settings named *_CREDENTIALS / CREDENTIAL
| Reported by: | venkatchalla06 | Owned by: | |
|---|---|---|---|
| Component: | Error reporting | Version: | dev |
| Severity: | Normal | Keywords: | |
| Cc: | venkatchalla06 | Triage Stage: | Unreviewed |
| Has patch: | no | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
SafeExceptionReporterFilter.hidden_settings (django/views/debug.py) redacts settings whose name matches the regex API|AUTH|TOKEN|KEY|SECRET|PASS|SIGNATURE|HTTP_COOKIE.
A flat setting whose name contains only CREDENTIAL(S) — for example GOOGLE_APPLICATION_CREDENTIALS or a project's own <SERVICE>_CREDENTIALS — is not matched, so its value is shown in the clear on the technical 500 page and in AdminEmailHandler error emails.
AWS_SECRET_ACCESS_KEY is already covered (via SECRET/KEY), so this only affects settings coined with the word "credential", but that is a common naming convention for service-account and database credential settings.
Proposed fix: add CREDENTIAL to the hidden_settings regex. Direct precedent: #35646 added AUTH and HTTP_COOKIE to this same list.
I have a patch (code + docs + tests) ready to submit once this ticket is triaged.
I think we need a solid example of a common Django package defining a setting which would then be rendered exposing a secret.
Folks can use the existing naming convention when defining their own settings. I don't think we should just keep increasing the list for every possible scenario