Project

General

Profile

Patch #44371 » 0001-Adds-key-parameter-to-the-list-of-filter_parameters-.patch

Marius BĂLTEANU, 2026-08-24 22:37

View differences:

config/application.rb
65 65
    config.encoding = "utf-8"
66 66

  
67 67
    # Configure sensitive parameters which will be filtered from the log file.
68
    config.filter_parameters += [:password, :salt, :twofa_totp_key]
68
    config.filter_parameters += [:password, :salt, :twofa_totp_key, /\Akey\z/]
69 69

  
70 70
    config.action_mailer.perform_deliveries = false
71 71

  
test/unit/lib/parameter_filtering_test.rb
1
# frozen_string_literal: true
2

  
3
# Redmine - project management software
4
# Copyright (C) 2006-  Jean-Philippe Lang
5
#
6
# This program is free software; you can redistribute it and/or
7
# modify it under the terms of the GNU General Public License
8
# as published by the Free Software Foundation; either version 2
9
# of the License, or (at your option) any later version.
10
#
11
# This program is distributed in the hope that it will be useful,
12
# but WITHOUT ANY WARRANTY; without even the implied warranty of
13
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14
# GNU General Public License for more details.
15
#
16
# You should have received a copy of the GNU General Public License
17
# along with this program; if not, write to the Free Software
18
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.
19

  
20
require_relative '../../test_helper'
21

  
22
class ParameterFilteringTest < ActiveSupport::TestCase
23
  def filter(params)
24
    ActiveSupport::ParameterFilter.new(Rails.application.config.filter_parameters).filter(params)
25
  end
26

  
27
  test "the key parameter should be filtered from logs" do
28
    filtered = filter('key' => '1234567890abcdef1234567890abcdef12345678')
29
    assert_equal '[FILTERED]', filtered['key']
30
  end
31

  
32
  test "passwords should be filtered from logs" do
33
    assert_equal '[FILTERED]', filter('password' => 'secret')['password']
34
    assert_equal '[FILTERED]', filter('sudo_password' => 'secret')['sudo_password']
35
  end
36

  
37
  test "salt should be filtered from logs" do
38
    assert_equal '[FILTERED]', filter('salt' => 'secret')['salt']
39
  end
40

  
41
  test "twofa_totp_key should be filtered from logs" do
42
    assert_equal '[FILTERED]', filter('twofa_totp_key' => 'secret')['twofa_totp_key']
43
  end
44

  
45
  test "parameters merely containing key should not be over-filtered" do
46
    assert_equal 'fixes', filter('keywords' => 'fixes')['keywords']
47
  end
48
end
    (1-1/1)