pydantic / pydantic/httpx2

_send_single_request logs sensitive data / leaks credentials

Open
#767 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1.5k
Forks
76
Avg merge
8h 59m
Merged PRs (30d)
24

Description

Originally opened by @Netherwhal on 2023-07-08 15:26:02 in encode/httpx

Logs should not leak sensitive credentials/data - especially not in with log-level info.

Unfortunately httpx will log the full URL of the HTTP request, including username and password.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the _send_single_request entry point and reproduce an HTTP request whose URL contains username and password while info logging is enabled. Trace the logging path and add a regression test for the reported case; done means sensitive credentials and data are not exposed in logs.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.