Skip to content

Redact credentials in audit event request metadata - #5535

Open
philippthun wants to merge 1 commit into
cloudfoundry:mainfrom
sap-contributions:redact-url-credentials-in-audit-events
Open

philippthun wants to merge 1 commit into
cloudfoundry:mainfrom
sap-contributions:redact-url-credentials-in-audit-events

Conversation

@philippthun

Copy link
Copy Markdown
Member

Custom buildpack URLs and user-provided service instance URLs may embed credentials (user:token@host) that leaked into audit event metadata in cleartext.

The app audit-event sanitizer obfuscated the legacy singular buildpack key and the v3 lifecycle.data.buildpack key, but not the v3 lifecycle.data.buildpacks array, so credentials leaked into audit.app.create and audit.app.update events.

User-provided service instance events redacted the credentials hash but left syslog_drain_url and route_service_url untouched, leaking any embedded credentials into audit.user_provided_service_instance.create and .update events.

Obfuscate the buildpacks array entries and the user-provided service instance URL fields with the existing URL secret obfuscator.

This change was developed with AI assistance; all code was reviewed and tested by me.

  • I have reviewed the contributing guide

  • I have viewed, signed, and submitted the Contributor License Agreement

  • I have made this pull request to the main branch

  • I have run all the unit tests using bundle exec rake

  • I have run CF Acceptance Tests

Custom buildpack URLs and user-provided service instance URLs may
embed credentials (user:token@host) that leaked into audit event
metadata in cleartext.

The app audit-event sanitizer obfuscated the legacy singular
buildpack key and the v3 lifecycle.data.buildpack key, but not the
v3 lifecycle.data.buildpacks array, so credentials leaked into
audit.app.create and audit.app.update events.

User-provided service instance events redacted the credentials
hash but left syslog_drain_url and route_service_url untouched,
leaking any embedded credentials into
audit.user_provided_service_instance.create and .update events.

Obfuscate the buildpacks array entries and the user-provided
service instance URL fields with the existing URL secret
obfuscator.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant