aio-libs / aio-libs/aiohttp

Proxy credentials are logged as clear text

Open
#5,399 2 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
16.5k
Forks
2.4k
Avg merge
17h 22m
Merged PRs (30d)
212

Description

🐞 **Describe the bug**

aiohttp logs proxy username/password as clear text when hitting a 503:

```console
aiohttp.client_exceptions.ClientHttpProxyError: 503, message=‘Service Unavailable’, url=URL(‘http://**proxyuser:proxypass**@myproxy.example.com:8080’)
```

💡 **To Reproduce**

1. Create an aiohttp session with a proxy that has a username and password
2. Hit an error such as a 503
3. Observe that the username and password are logged in clear text

💡 **Expected behavior**

aiohttp obscures the password

📋 **Logs/tracebacks**

```python-traceback
File “/usr/lib64/python3.6/site-packages/aiohttp/client.py”, line 1012, in aenter
self._resp = await self._coro
File “/usr/lib64/python3.6/site-packages/aiohttp/client.py”, line 483, in _request
timeout=real_timeout
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 523, in connect
proto = await self._create_connection(req, traces, timeout)
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 856, in _create_connection
req, traces, timeout)
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 1083, in _create_proxy_connection
headers=resp.headers)
aiohttp.client_exceptions.ClientHttpProxyError: 503, message=‘Service Unavailable’, url=URL(‘http://**proxyuser:proxypass**@myproxy.example.com:8080’)
```

📋 **Your version of the Python**

3.6

📋 **Your version of the aiohttp/yarl/multidict distributions**

aiohttp 3.7.3

📋 **Additional context**

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.