Bug 2013759

Summary: Password to git is visible in export summary
Product: Red Hat Satellite Reporter: Peter Dragun <pdragun>
Component: Templates PluginAssignee: Adam Ruzicka <aruzicka>
Status: VERIFIED --- QA Contact: Peter Ondrejka <pondrejk>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 6.10.0CC: aruzicka, mhulan, pcreech
Target Milestone: 6.14.0Keywords: Security, Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: rubygem-foreman_templates-9.4.0-1 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
screenshot none

Description Peter Dragun 2021-10-13 16:35:52 UTC
Created attachment 1832647 [details]
screenshot

Description of problem:
Password(token) to git is visible in export summary if using http authentication.

Version-Release number of selected component (if applicable):


How reproducible:
always

Steps to Reproduce:
1. Navigate to Hosts -> Sync Templates
2. Set Action type to export
3. Export templates to git using http with authentication
4. Submit

Actual results:
Password is visible in url

Expected results:
Password should be redacted

Additional info:

Comment 2 Brad Buckingham 2022-11-03 21:47:07 UTC
Upon review of our valid but aging backlog the Satellite Team has concluded that this Bugzilla does not meet the criteria for a resolution in the near term, and are planning to close in a month. This message may be a repeat of a previous update and the bug is again being considered to be closed. If you have any concerns about this, please contact your Red Hat Account team.  Thank you.

Comment 5 Adam Ruzicka 2023-01-13 14:48:42 UTC
The upstream PR was merged, moving to POST.

Comment 6 Peter Ondrejka 2023-08-09 14:30:04 UTC
Verified on Sat 6.14 snap 10, the password is now redacted in the template export result summary