﻿id	summary	reporter	owner	description	type	status	component	version	severity	resolution	keywords	cc	stage	has_patch	needs_docs	needs_tests	needs_better_patch	easy	ui_ux
37398	SafeExceptionReporterFilter does not cleanse settings named *_CREDENTIALS / CREDENTIAL	venkatchalla06		"`SafeExceptionReporterFilter.hidden_settings` (django/views/debug.py) redacts settings whose name matches the regex `API|AUTH|TOKEN|KEY|SECRET|PASS|SIGNATURE|HTTP_COOKIE`.

A flat setting whose name contains only `CREDENTIAL(S)` — for example `GOOGLE_APPLICATION_CREDENTIALS` or a project's own `<SERVICE>_CREDENTIALS` — is not matched, so its value is shown in the clear on the technical 500 page and in `AdminEmailHandler` error emails.

`AWS_SECRET_ACCESS_KEY` is already covered (via SECRET/KEY), so this only affects settings coined with the word ""credential"", but that is a common naming convention for service-account and database credential settings.

Proposed fix: add `CREDENTIAL` to the `hidden_settings` regex. Direct precedent: #35646 added AUTH and HTTP_COOKIE to this same list.

I have a patch (code + docs + tests) ready to submit once this ticket is triaged."	Bug	closed	Error reporting	dev	Normal	wontfix		venkatchalla06	Unreviewed	0	0	0	0	0	0
