Support overriding the default SanitizingFunction
See gh-30006
This commit is contained in:
committed by
Andy Wilkinson
parent
a5d900d0af
commit
fb9112c891
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2021 the original author or authors.
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -184,13 +184,18 @@ public class Sanitizer {
|
||||
* @since 2.6.0
|
||||
*/
|
||||
public Object sanitize(SanitizableData data) {
|
||||
if (data.getValue() == null) {
|
||||
Object value = data.getValue();
|
||||
if (value == null) {
|
||||
return null;
|
||||
}
|
||||
for (SanitizingFunction sanitizingFunction : this.sanitizingFunctions) {
|
||||
data = sanitizingFunction.apply(data);
|
||||
Object sanitizedValue = data.getValue();
|
||||
if (!value.equals(sanitizedValue)) {
|
||||
return sanitizedValue;
|
||||
}
|
||||
}
|
||||
return data.getValue();
|
||||
return value;
|
||||
}
|
||||
|
||||
private boolean keyIsUriWithUserInfo(Pattern pattern) {
|
||||
|
||||
@@ -293,7 +293,7 @@ class ConfigurationPropertiesReportEndpointTests {
|
||||
new ApplicationContextRunner().withUserConfiguration(CustomSanitizingEndpointConfig.class,
|
||||
SanitizingFunctionConfiguration.class, TestPropertiesConfiguration.class)
|
||||
.run(assertProperties("test", (properties) -> {
|
||||
assertThat(properties.get("dbPassword")).isEqualTo("******");
|
||||
assertThat(properties.get("dbPassword")).isEqualTo("$$$");
|
||||
assertThat(properties.get("myTestProperty")).isEqualTo("$$$");
|
||||
}));
|
||||
}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2021 the original author or authors.
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -16,7 +16,9 @@
|
||||
|
||||
package org.springframework.boot.actuate.endpoint;
|
||||
|
||||
import java.util.ArrayList;
|
||||
import java.util.Collections;
|
||||
import java.util.List;
|
||||
import java.util.stream.Stream;
|
||||
|
||||
import org.junit.jupiter.api.Test;
|
||||
@@ -87,6 +89,39 @@ class SanitizerTests {
|
||||
assertThat(sanitizer.sanitize(hello)).isEqualTo("abc");
|
||||
}
|
||||
|
||||
@Test
|
||||
void overridingDefaultSanitizingFunction() {
|
||||
Sanitizer sanitizer = new Sanitizer(Collections.singletonList((data) -> {
|
||||
if (data.getKey().equals("password")) {
|
||||
return data.withValue("------");
|
||||
}
|
||||
return data;
|
||||
}));
|
||||
SanitizableData password = new SanitizableData(null, "password", "123456");
|
||||
assertThat(sanitizer.sanitize(password)).isEqualTo("------");
|
||||
}
|
||||
|
||||
@Test
|
||||
void whenValueSanitizedLaterSanitizingFunctionsShouldBeSkipped() {
|
||||
final String sameKey = "custom";
|
||||
List<SanitizingFunction> sanitizingFunctions = new ArrayList<>();
|
||||
sanitizingFunctions.add((data) -> {
|
||||
if (data.getKey().equals(sameKey)) {
|
||||
return data.withValue("------");
|
||||
}
|
||||
return data;
|
||||
});
|
||||
sanitizingFunctions.add((data) -> {
|
||||
if (data.getKey().equals(sameKey)) {
|
||||
return data.withValue("******");
|
||||
}
|
||||
return data;
|
||||
});
|
||||
Sanitizer sanitizer = new Sanitizer(sanitizingFunctions);
|
||||
SanitizableData custom = new SanitizableData(null, sameKey, "123456");
|
||||
assertThat(sanitizer.sanitize(custom)).isEqualTo("------");
|
||||
}
|
||||
|
||||
@ParameterizedTest(name = "key = {0}")
|
||||
@MethodSource("matchingUriUserInfoKeys")
|
||||
void uriWithSingleValueWithPasswordShouldBeSanitized(String key) {
|
||||
|
||||
Reference in New Issue
Block a user