Sanitize password in URI properties
See gh-17939
This commit is contained in:
committed by
Madhura Bhave
parent
0fee0ca71c
commit
d49a2ec98e
@@ -16,6 +16,7 @@
|
||||
|
||||
package org.springframework.boot.actuate.context.properties;
|
||||
|
||||
import java.net.URI;
|
||||
import java.time.Duration;
|
||||
import java.util.ArrayList;
|
||||
import java.util.Arrays;
|
||||
@@ -46,6 +47,7 @@ import static org.assertj.core.api.Assertions.assertThat;
|
||||
* @author Dave Syer
|
||||
* @author Andy Wilkinson
|
||||
* @author Stephane Nicoll
|
||||
* @author HaiTao Zhang
|
||||
*/
|
||||
class ConfigurationPropertiesReportEndpointTests {
|
||||
|
||||
@@ -174,6 +176,22 @@ class ConfigurationPropertiesReportEndpointTests {
|
||||
});
|
||||
}
|
||||
|
||||
@Test
|
||||
void sanitizedUriWithSensitiveInfo() {
|
||||
load((context, properties) -> {
|
||||
Map<String, Object> nestedProperties = properties.getBeans().get("testProperties").getProperties();
|
||||
assertThat(nestedProperties.get("sensitiveUri")).isEqualTo("http://user:******@localhost:8080");
|
||||
});
|
||||
}
|
||||
|
||||
@Test
|
||||
void sanitizedUriWithNoPassword() {
|
||||
load((context, properties) -> {
|
||||
Map<String, Object> nestedProperties = properties.getBeans().get("testProperties").getProperties();
|
||||
assertThat(nestedProperties.get("noPasswordUri")).isEqualTo("http://user:******@localhost:8080");
|
||||
});
|
||||
}
|
||||
|
||||
@Test
|
||||
@SuppressWarnings("unchecked")
|
||||
void listsOfListsAreSanitized() {
|
||||
@@ -266,6 +284,10 @@ class ConfigurationPropertiesReportEndpointTests {
|
||||
|
||||
private Duration duration = Duration.ofSeconds(10);
|
||||
|
||||
private URI sensitiveUri = URI.create("http://user:password@localhost:8080");
|
||||
|
||||
private URI noPasswordUri = URI.create("http://user:p@localhost:8080");
|
||||
|
||||
TestProperties() {
|
||||
this.secrets.put("mine", "myPrivateThing");
|
||||
this.secrets.put("yours", "yourPrivateThing");
|
||||
@@ -377,6 +399,22 @@ class ConfigurationPropertiesReportEndpointTests {
|
||||
this.duration = duration;
|
||||
}
|
||||
|
||||
public void setSensitiveUri(URI sensitiveUri) {
|
||||
this.sensitiveUri = sensitiveUri;
|
||||
}
|
||||
|
||||
public URI getSensitiveUri() {
|
||||
return this.sensitiveUri;
|
||||
}
|
||||
|
||||
public void setNoPasswordUri(URI noPasswordUri) {
|
||||
this.noPasswordUri = noPasswordUri;
|
||||
}
|
||||
|
||||
public URI getNoPasswordUri() {
|
||||
return this.noPasswordUri;
|
||||
}
|
||||
|
||||
public static class Hidden {
|
||||
|
||||
private String mine = "mySecret";
|
||||
|
||||
@@ -40,6 +40,8 @@ class SanitizerTests {
|
||||
assertThat(sanitizer.sanitize("sometoken", "secret")).isEqualTo("******");
|
||||
assertThat(sanitizer.sanitize("find", "secret")).isEqualTo("secret");
|
||||
assertThat(sanitizer.sanitize("sun.java.command", "--spring.redis.password=pa55w0rd")).isEqualTo("******");
|
||||
assertThat(sanitizer.sanitize("my.uri", "http://user:password@localhost:8080"))
|
||||
.isEqualTo("http://user:******@localhost:8080");
|
||||
}
|
||||
|
||||
@Test
|
||||
|
||||
@@ -49,6 +49,7 @@ import static org.assertj.core.api.Assertions.assertThat;
|
||||
* @author Stephane Nicoll
|
||||
* @author Madhura Bhave
|
||||
* @author Andy Wilkinson
|
||||
* @author HaiTao Zhang
|
||||
*/
|
||||
class EnvironmentEndpointTests {
|
||||
|
||||
@@ -244,6 +245,14 @@ class EnvironmentEndpointTests {
|
||||
assertThat(sources.get("two").getProperties().get("a").getValue()).isEqualTo("apple");
|
||||
}
|
||||
|
||||
@Test
|
||||
void uriPropertryWithSensitiveInfo() {
|
||||
ConfigurableEnvironment environment = new StandardEnvironment();
|
||||
TestPropertyValues.of("sensitive.uri=http://user:password@localhost:8080").applyTo(environment);
|
||||
EnvironmentEntryDescriptor descriptor = new EnvironmentEndpoint(environment).environmentEntry("sensitive.uri");
|
||||
assertThat(descriptor.getProperty().getValue()).isEqualTo("http://user:******@localhost:8080");
|
||||
}
|
||||
|
||||
private static ConfigurableEnvironment emptyEnvironment() {
|
||||
StandardEnvironment environment = new StandardEnvironment();
|
||||
environment.getPropertySources().remove(StandardEnvironment.SYSTEM_ENVIRONMENT_PROPERTY_SOURCE_NAME);
|
||||
|
||||
Reference in New Issue
Block a user