Support Robot Framework (SeleniumLibrary) `Secret` values in `Open Browser`

Đang mở
#1,993 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
58/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
testing-qa

Hướng nghiên cứu

Bắt đầu từ phần triển khai keyword Open Browser của SeleniumLibrary và theo dõi cách đối số URL của nó được truyền tới Selenium. Kiểm tra cách các giá trị Secret được biểu diễn và xử lý trong Robot Framework 7.4.2, sau đó bổ sung coverage cho ví dụ Secret URL được cung cấp. Hoàn thành khi Open Browser chấp nhận trực tiếp Secret, đồng thời các log của Robot Framework vẫn tiếp tục che URL.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description

SeleniumLibrary currently does not support Robot Framework Secret values when they are passed to keywords expecting string arguments.

For example, when using a Secret as the url argument of Open Browser, the browser is not opened successfully.

To make it work, I have to explicitly use ${url.value} instead of ${url}. However, this defeats the purpose of using Secret, because the URL is then logged in clear text in Robot Framework log files.

Example

*** Settings ***
Library    SeleniumLibrary

*** Test Cases ***
Open Browser With Secret URL
    ${url}=    Get Secret    https://example.com?token=secret-token
    Open Browser    ${url}    Firefox

Current behavior

Passing a Secret object directly causes the keyword to fail.

A subsequent keyword then reports:

[FAIL] No browser is open.

The only workaround is to use:

Open Browser    ${url.value}    Firefox

This opens the browser correctly, but the secret URL is no longer protected and is written in clear text to Robot Framework log files.

Expected behavior

Keywords accepting string arguments should also accept Robot Framework Secret values.

SeleniumLibrary should automatically unwrap the Secret internally before passing the value to Selenium, while preserving Robot Framework's secret masking in logs and reports.

This would allow users to use sensitive URLs (for example, URLs containing authentication tokens or embedded credentials) without exposing them in log files.

Environment

  • Robot Framework: 7.4.2
  • SeleniumLibrary: 6.9.0

Additional question

If this is not something that should be implemented in SeleniumLibrary, could you please advise whether support for Secret values should instead be implemented in Robot Framework?

Ngôn ngữ chính
Python
Star
1.5k
Fork
787
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của robotframework/SeleniumLibrary

Tất cả issue của robotframework/SeleniumLibrary

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.