Try to remove secrets from http.debug.#8222
Merged
bors merged 1 commit intorust-lang:masterfrom May 8, 2020
Merged
Conversation
|
(rust_highfive has picked a reviewer for you, use r? to override) |
Member
|
@bors: r+ |
Contributor
|
📌 Commit b3616c0 has been approved by |
Contributor
Contributor
|
☀️ Test successful - checks-azure |
bors
added a commit
that referenced
this pull request
May 6, 2023
Fix redacting tokens in http debug. Unfortunately it seems like #8222 didn't properly redact tokens when connecting to an http2 server. There were multiple problems: * For some reason, curl changes the authorization header to be lowercase when using http2. * Curl also logs the h2h3 lines separately with a different syntax. This fixes it by checking for these additional cases. This also adds a test, but it doesn't actually detect this problem because we don't have an http2 server handy. You can test this yourself by running `CARGO_LOG=trace CARGO_HTTP_DEBUG=true cargo publish --token a-unique-token --allow-dirty --no-verify`, and verifying the output does not contain the given token text.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This tries to remove some private data (such as tokens) from the
http.debugoutput.