aio-libs / aio-libs/aiohttp

Proxy credentials are logged as clear text

未关闭
#5,399 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Python
星标
16.5k
派生
2.4k
平均合并
17 小时 22 分钟
30 天内合并 PR
212

描述

🐞 **Describe the bug**

aiohttp logs proxy username/password as clear text when hitting a 503:

```console
aiohttp.client_exceptions.ClientHttpProxyError: 503, message=‘Service Unavailable’, url=URL(‘http://**proxyuser:proxypass**@myproxy.example.com:8080’)
```

💡 **To Reproduce**

1. Create an aiohttp session with a proxy that has a username and password
2. Hit an error such as a 503
3. Observe that the username and password are logged in clear text

💡 **Expected behavior**

aiohttp obscures the password

📋 **Logs/tracebacks**

```python-traceback
File “/usr/lib64/python3.6/site-packages/aiohttp/client.py”, line 1012, in aenter
self._resp = await self._coro
File “/usr/lib64/python3.6/site-packages/aiohttp/client.py”, line 483, in _request
timeout=real_timeout
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 523, in connect
proto = await self._create_connection(req, traces, timeout)
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 856, in _create_connection
req, traces, timeout)
File “/usr/lib64/python3.6/site-packages/aiohttp/connector.py”, line 1083, in _create_proxy_connection
headers=resp.headers)
aiohttp.client_exceptions.ClientHttpProxyError: 503, message=‘Service Unavailable’, url=URL(‘http://**proxyuser:proxypass**@myproxy.example.com:8080’)
```

📋 **Your version of the Python**

3.6

📋 **Your version of the aiohttp/yarl/multidict distributions**

aiohttp 3.7.3

📋 **Additional context**

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。