Skip to content
This repository has been archived by the owner on Jan 21, 2022. It is now read-only.

Reporter for current version of cf-test-helpers does not redact sensitive data #5

Open
Freakin opened this issue Aug 15, 2017 · 0 comments

Comments

@Freakin
Copy link

Freakin commented Aug 15, 2017

Specifically for InitiateUserContext, the NewCmdRunner which performs the cf auth command reports the password in clear text.

This coupled with the inability to re-use an existing org/space and user and instead require admin credentials will expose sensitive data in logs.

Newer versions of cf-test-helpers (used by cf-smoke-tests) leverage a Redacting Reporter which removes sensitive information from output.

Our organization runs mysql lifecycle tests from concourse on a regular basis and without making local changes to vendored cf-test-helpers to use a regular user context our admin credentials would be exposed in concourse task logs.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant