Do not reveal sensitive Data - #1597
Open
cocker-cc wants to merge 1 commit into
Open
Conversation
cocker-cc
requested review from
a team,
SimonHoenscheid,
alexjfisher,
bastelfreak,
deric,
ekohl and
smortex
as code owners
May 10, 2024 21:08
bastelfreak
previously approved these changes
May 10, 2024
deric
previously approved these changes
May 13, 2024
smortex
previously approved these changes
May 13, 2024
SimonHoenscheid
previously approved these changes
May 16, 2024
cocker-cc
force-pushed
the
Sensitive_Data
branch
from
June 13, 2024 19:38
bb77bb2 to
6ce2cb1
Compare
Member
|
@cocker-cc : I've added this PR to the list for engineering to review when they have capacity, but I'm noticing that the branch has conflicts that need resolving. Any chance you could update to the latest? |
cocker-cc
dismissed stale reviews from SimonHoenscheid, deric, smortex, and bastelfreak
via
July 27, 2026 20:24
c1d6149
cocker-cc
force-pushed
the
Sensitive_Data
branch
from
July 27, 2026 20:24
6ce2cb1 to
c1d6149
Compare
Member
|
This needs #1691 in order for tests to work. |
"auth_option" may contain sensitive Data, f.e. LDAP-Password. So let auth_option accept Puppet-Type Sensitive. The consuming EPP is able to handle sensitive Data natively, and will return the rendered Template as Sensitive[String] then, which the Resource "file" also is able to handle.
cocker-cc
force-pushed
the
Sensitive_Data
branch
from
August 7, 2026 20:43
c1d6149 to
456bc50
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
auth_optionmay contain sensitive Data, f.e. LDAP-Password. So letauth_optionaccept Puppet-TypeSensitive. The consuming EPP is able to handle sensitive Data natively, and will return the rendered Template asSensitive[String]then, which the Resourcefilealso is able to handle.Checklist
pdk validatepdk test unit