Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sanitize id for project access token resource #409

Merged
merged 2 commits into from
Sep 5, 2024

Conversation

pawelsz-rb
Copy link
Collaborator

@pawelsz-rb pawelsz-rb commented Sep 3, 2024

Description of the change

terraform ID for a project access token resource was set to access token, which was not really secure causing a leaking token. Now it's sanitized by computing md5 sum on that token. Change was tested, it's backward compatible.

Type of change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Maintenance
  • New release

Checklists

Development

  • Lint rules pass locally
  • The code changed/added as part of this pull request has been covered with tests
  • All tests related to the changed code pass in development

Code review

  • This pull request has a descriptive title and information useful to a reviewer. There may be a screenshot or screencast attached
  • "Ready for review" label attached to the PR and reviewers assigned
  • Issue from task tracker has a link to this pull request
  • Changes have been reviewed by at least one other engineer

@coveralls
Copy link

coveralls commented Sep 3, 2024

Pull Request Test Coverage Report for Build 10678663426

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 92.097%

Totals Coverage Status
Change from base Build 9972229186: 0.0%
Covered Lines: 1480
Relevant Lines: 1607

💛 - Coveralls

Copy link

codeclimate bot commented Sep 3, 2024

Code Climate has analyzed commit 32838f2 and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 92.0% (0.0% change).

View more on Code Climate.

@pawelsz-rb pawelsz-rb changed the title fix id for project access token resource sanitize id for project access token resource Sep 3, 2024
Copy link
Contributor

@waltjones waltjones left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks fine since md5 collisions aren't a security issue in this case.

@pawelsz-rb pawelsz-rb merged commit cec9f3d into master Sep 5, 2024
21 checks passed
@pawelsz-rb pawelsz-rb deleted the pawel/fix_id_for_access_token branch September 5, 2024 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants