-
Notifications
You must be signed in to change notification settings - Fork 8
Filter out any password from the manifest #11
Filter out any password from the manifest #11
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, good catch @agrare
maybe add a small spec to show that password fields are filtered. |
@abellotti specs don't seem to be passing in this repo |
@agrare @abellotti yeah, I disabled the Ruby checks in Travis because I never got them to work when I started this plugin.. I was going to ask for some help figuring that out: #2 |
bef4fbd
to
61c151f
Compare
spec/manageiq
Outdated
@@ -0,0 +1 @@ | |||
/home/agrare/src/manageiq/manageiq |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
probably shouldn't be here.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ugh yeah, the .gitignore for this repo is all wrong
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed
Mitigate issues where someone could upload a manifest with the intention of collecting passwords from the database by stripping out any of the "password" fields defined in Vmdb::SettingsWalker
61c151f
to
0331fa1
Compare
Okay @abellotti if you change vmdb_plugin? to true this passes rspec locally |
Checked commits agrare/cfme-migration_analytics@0331fa1~...b8d59cd with ruby 2.4.6, rubocop 0.69.0, haml-lint 0.20.0, and yamllint 1.10.0 **
|
…nifest Filter out any password from the manifest (cherry picked from commit 976dd3b)
Ivanchuk backport details:
|
Mitigate issues where someone could upload a manifest with the intention
of collecting passwords from the database by stripping out any of the
"password" fields defined in Vmdb::SettingsWalker
Depends on ManageIQ/manageiq#19103