Repository navigation
fix(cli): apply URL redaction to all remote template display paths - #12698
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
There was a problem hiding this comment.
Pull request overview
This PR strengthens rad CLI security by ensuring remote template URLs are consistently redacted everywhere they’re displayed or incorporated into generated output, preventing credential leakage (e.g., SAS tokens, basic-auth userinfo) into terminals, CI logs, and files.
Changes:
- Introduces
bicep.RedactTemplatePathand routes CLI display strings (deploy progress/errors, bicep publish logs, app graph compile messages) through it. - Introduces
bicep.TemplateFileNameand uses it when deriving output filenames/template names so URL queries/fragments never reach disk or generated YAML. - Improves remote download error handling to avoid leaking raw request URLs via
*url.Error, and expands unit tests around redaction behavior.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| pkg/cli/cmd/deploy/deploy.go | Redacts template path in deploy progress text and missing-parameter error output. |
| pkg/cli/cmd/deploy/deploy_test.go | Adds coverage asserting deploy progress text does not include URL credentials. |
| pkg/cli/cmd/bicep/publish/publish.go | Redacts template argument in publish logs and error messages. |
| pkg/cli/cmd/bicep/generatekubernetesmanifest/generatekubernetesmanifest.go | Uses TemplateFileName to prevent URL query/fragment content from influencing filenames and manifest output. |
| pkg/cli/cmd/app/graph/graph.go | Redacts template path in compile log/error output. |
| pkg/cli/cmd/app/graph/preview/graph.go | Redacts template path in compile log/error output for preview mode. |
| pkg/cli/bicep/types.go | Adds redaction/template-name helpers, drops fragments during redaction, and unwraps *url.Error to avoid URL leakage. |
| pkg/cli/bicep/types_test.go | Adds tests for redaction, filename derivation, and credential-safe error paths. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #12698 +/- ##
==========================================
+ Coverage 54.31% 54.34% +0.03%
==========================================
Files 770 770
Lines 51240 51263 +23
==========================================
+ Hits 27829 27857 +28
+ Misses 20795 20793 -2
+ Partials 2616 2613 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
2780020 to
0d3b1dc
Compare
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Summary
Applies the existing URL redaction to every place
raddisplays a template argument, so credentialsembedded in a remote template URL are no longer written to the terminal, to CI logs, or into
generated files.
pr #12676 added remote-template support (
rad deploy https://host/app.bicep) along with aredactURLhelper, because private template URLs commonly carry an Azure SAS token as a signed query parameter
or basic-auth userinfo. That redaction was applied inside the download path only. The raw URL was
still formatted into the
Building %s...step, several error messages, therad deployprogresstext and failure error, the
rad bicep publishmessages, and therad app graphcompile output.This change introduces
bicep.RedactTemplatePath(a no-op for local paths, redacting forhttp(s)URLs) and routes every display site through it, plus three related leaks found while wiring it up:
rad bicep generate-kubernetes-manifestderived its output file name withfilepath.Base/Exton the raw URL. Because
filepath.Exttakes the last dot, a query value containing a dot survivedinto a real file name on disk and into the log line:
app.bicep?sig=abc.yaml. A newbicep.TemplateFileNameparses the URL and drops the query and fragment entirely, so a file nameis never derived from credential text.
*url.Error, whose message embeds the raw request URL.The redacted URL and the credential were printed side by side:
failed to download template from "…?sig=redacted": Get "…?sig=TOPSECRET": dial tcp: ….Both transport and body-read errors now unwrap through the existing
urlParseReasonhelper.redactURLpreserved the URL fragment. It is never needed to fetch a template, so it is dropped.No behavior changes for local file paths:
isRemoteURLmatches onlyhttp://andhttps://prefixes, so local paths (including Windows
C:\...paths and names containing?) pass throughuntouched.
Reason for change
A SAS token or basic-auth credential supplied to
rad deploywas echoed to stdout and into CI joblogs. In CI the URL is typically injected from a secret or environment variable, so the CLI printing
it is often the first time the value is written to a retained log, and GitHub Actions secret masking
does not reliably cover dynamically generated SAS URLs. The redaction control added in #12676 was
intended to prevent exactly this, but was only wired into part of the code path.
Fixes: follow up to pr #12676
How to test
rad deploy 'https://<host>/app.bicep?sig=SECRET'— the build step, progress text, and anydeployment failure show
sig=redacted, never the token.rad deploy 'https://<unreachable-host>/app.bicep?sig=SECRET'— the connection error is reportedwithout the token.
rad bicep generate-kubernetes-manifest 'https://<host>/app.bicep?sig=a.b'— the generated fileis
app.yaml, and neither the file name nor the manifest contents contain the token.rad bicep publishandrad app graphwith a credentialed URL — all messages are redacted.rad deploy ./app.bicepand./app.json— local output is unchanged.File change summary
pkg/cli/bicep/types.goRedactTemplatePathandTemplateFileName; use a redacteddisplayPathat all four display sites inPrepareTemplate; drop the fragment inredactURL; unwrap*url.ErrorviaurlParseReasonon the transport and body-read error paths.pkg/cli/cmd/deploy/deploy.gopkg/cli/cmd/bicep/publish/publish.gopkg/cli/cmd/app/graph/graph.go,pkg/cli/cmd/app/graph/preview/graph.goCompiling %slog and the compile-failure error.pkg/cli/cmd/bicep/generatekubernetesmanifest/generatekubernetesmanifest.gobicep.TemplateFileNameso URL query text never reaches a file name or the generated YAML.pkg/cli/bicep/types_test.goTest_RedactTemplatePath,Test_TemplateFileName,Test_PrepareTemplate_RemoteErrorRedactsCredentials,Test_downloadTemplate_TransportErrorRedactsCredentials, and a fragment case.pkg/cli/cmd/deploy/deploy_test.goTest_Runsubtest asserting the captureddeploy.Options.ProgressTextcontainssig=redactedand not the token.