Skip to content

fix(cli): apply URL redaction to all remote template display paths - #12698

Merged
lakshmimsft merged 3 commits into
mainfrom
lakshmimsft/redact-remote-template-url
Aug 18, 2026
Merged

lakshmimsft merged 3 commits into
mainfrom
lakshmimsft/redact-remote-template-url

Conversation

@lakshmimsft

Copy link
Copy Markdown
Contributor

Summary

Applies the existing URL redaction to every place rad displays a template argument, so credentials
embedded in a remote template URL are no longer written to the terminal, to CI logs, or into
generated files.

pr #12676 added remote-template support (rad deploy https://host/app.bicep) along with a redactURL
helper, because private template URLs commonly carry an Azure SAS token as a signed query parameter
or basic-auth userinfo. That redaction was applied inside the download path only. The raw URL was
still formatted into the Building %s... step, several error messages, the rad deploy progress
text and failure error, the rad bicep publish messages, and the rad app graph compile output.

This change introduces bicep.RedactTemplatePath (a no-op for local paths, redacting for http(s)
URLs) and routes every display site through it, plus three related leaks found while wiring it up:

  • rad bicep generate-kubernetes-manifest derived its output file name with filepath.Base/Ext
    on the raw URL. Because filepath.Ext takes the last dot, a query value containing a dot survived
    into a real file name on disk and into the log line: app.bicep?sig=abc.yaml. A new
    bicep.TemplateFileName parses the URL and drops the query and fragment entirely, so a file name
    is never derived from credential text.
  • A download transport failure returned a *url.Error, whose message embeds the raw request URL.
    The redacted URL and the credential were printed side by side:
    failed to download template from "…?sig=redacted": Get "…?sig=TOPSECRET": dial tcp: ….
    Both transport and body-read errors now unwrap through the existing urlParseReason helper.
  • redactURL preserved the URL fragment. It is never needed to fetch a template, so it is dropped.

No behavior changes for local file paths: isRemoteURL matches only http:// and https://
prefixes, so local paths (including Windows C:\... paths and names containing ?) pass through
untouched.

Reason for change

A SAS token or basic-auth credential supplied to rad deploy was echoed to stdout and into CI job
logs. In CI the URL is typically injected from a secret or environment variable, so the CLI printing
it is often the first time the value is written to a retained log, and GitHub Actions secret masking
does not reliably cover dynamically generated SAS URLs. The redaction control added in #12676 was
intended to prevent exactly this, but was only wired into part of the code path.

Fixes: follow up to pr #12676

How to test

  1. rad deploy 'https://<host>/app.bicep?sig=SECRET' — the build step, progress text, and any
    deployment failure show sig=redacted, never the token.
  2. rad deploy 'https://<unreachable-host>/app.bicep?sig=SECRET' — the connection error is reported
    without the token.
  3. rad bicep generate-kubernetes-manifest 'https://<host>/app.bicep?sig=a.b' — the generated file
    is app.yaml, and neither the file name nor the manifest contents contain the token.
  4. rad bicep publish and rad app graph with a credentialed URL — all messages are redacted.
  5. rad deploy ./app.bicep and ./app.json — local output is unchanged.

File change summary

File Summary of change
pkg/cli/bicep/types.go Add exported RedactTemplatePath and TemplateFileName; use a redacted displayPath at all four display sites in PrepareTemplate; drop the fragment in redactURL; unwrap *url.Error via urlParseReason on the transport and body-read error paths.
pkg/cli/cmd/deploy/deploy.go Redact the template path in both progress-text branches and in the deployment-failure error.
pkg/cli/cmd/bicep/publish/publish.go Redact the file argument in the prepare error, both publish errors, and the success log.
pkg/cli/cmd/app/graph/graph.go, pkg/cli/cmd/app/graph/preview/graph.go Redact the path in the Compiling %s log and the compile-failure error.
pkg/cli/cmd/bicep/generatekubernetesmanifest/generatekubernetesmanifest.go Derive the destination file name and the manifest template name from bicep.TemplateFileName so URL query text never reaches a file name or the generated YAML.
pkg/cli/bicep/types_test.go Add Test_RedactTemplatePath, Test_TemplateFileName, Test_PrepareTemplate_RemoteErrorRedactsCredentials, Test_downloadTemplate_TransportErrorRedactsCredentials, and a fragment case.
pkg/cli/cmd/deploy/deploy_test.go Add a Test_Run subtest asserting the captured deploy.Options.ProgressText contains sig=redacted and not the token.

@lakshmimsft lakshmimsft added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Aug 17, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@lakshmimsft
lakshmimsft marked this pull request as ready for review August 17, 2026 21:35
@lakshmimsft
lakshmimsft requested review from a team as code owners August 17, 2026 21:35
Copilot AI lite review requested due to automatic review settings August 17, 2026 21:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR strengthens rad CLI security by ensuring remote template URLs are consistently redacted everywhere they’re displayed or incorporated into generated output, preventing credential leakage (e.g., SAS tokens, basic-auth userinfo) into terminals, CI logs, and files.

Changes:

  • Introduces bicep.RedactTemplatePath and routes CLI display strings (deploy progress/errors, bicep publish logs, app graph compile messages) through it.
  • Introduces bicep.TemplateFileName and uses it when deriving output filenames/template names so URL queries/fragments never reach disk or generated YAML.
  • Improves remote download error handling to avoid leaking raw request URLs via *url.Error, and expands unit tests around redaction behavior.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
pkg/cli/cmd/deploy/deploy.go Redacts template path in deploy progress text and missing-parameter error output.
pkg/cli/cmd/deploy/deploy_test.go Adds coverage asserting deploy progress text does not include URL credentials.
pkg/cli/cmd/bicep/publish/publish.go Redacts template argument in publish logs and error messages.
pkg/cli/cmd/bicep/generatekubernetesmanifest/generatekubernetesmanifest.go Uses TemplateFileName to prevent URL query/fragment content from influencing filenames and manifest output.
pkg/cli/cmd/app/graph/graph.go Redacts template path in compile log/error output.
pkg/cli/cmd/app/graph/preview/graph.go Redacts template path in compile log/error output for preview mode.
pkg/cli/bicep/types.go Adds redaction/template-name helpers, drops fragments during redaction, and unwraps *url.Error to avoid URL leakage.
pkg/cli/bicep/types_test.go Adds tests for redaction, filename derivation, and credential-safe error paths.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/cli/bicep/types_test.go
@github-actions

github-actions Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Functional Tests - samples-noncloud

3 tests  ±0   3 ✅ ±0   1m 25s ⏱️ ±0s
1 suites ±0   0 💤 ±0 
1 files   ±0   0 ❌ ±0 

Results for commit 0d3b1dc. ± Comparison against base commit 5ba29da.

♻️ This comment has been updated with latest results.

@github-actions

github-actions Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ± 0    457 suites  ±0   7m 33s ⏱️ + 1m 8s
6 284 tests +21  6 282 ✅ +21  2 💤 ±0  0 ❌ ±0 
7 517 runs  +22  7 515 ✅ +22  2 💤 ±0  0 ❌ ±0 

Results for commit 0d3b1dc. ± Comparison against base commit 5ba29da.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.54545% with 9 lines in your changes missing coverage. Please review.
✅ Project coverage is 54.34%. Comparing base (5ba29da) to head (0d3b1dc).

Files with missing lines Patch % Lines
pkg/cli/cmd/bicep/publish/publish.go 0.00% 5 Missing ⚠️
pkg/cli/bicep/types.go 84.61% 4 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main   #12698      +/-   ##
==========================================
+ Coverage   54.31%   54.34%   +0.03%     
==========================================
  Files         770      770              
  Lines       51240    51263      +23     
==========================================
+ Hits        27829    27857      +28     
+ Misses      20795    20793       -2     
+ Partials     2616     2613       -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Comment thread pkg/cli/bicep/types.go Outdated
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
Signed-off-by: lakshmimsft <ljavadekar@microsoft.com>
@lakshmimsft
lakshmimsft force-pushed the lakshmimsft/redact-remote-template-url branch from 2780020 to 0d3b1dc Compare August 17, 2026 23:25
@radius-functional-tests

radius-functional-tests Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 0d3b1dc
Unique ID funca36caee682
Image tag pr-funca36caee682
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funca36caee682
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funca36caee682
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funca36caee682
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funca36caee682
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funca36caee682
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

@brooke-hamilton
brooke-hamilton added this pull request to the merge queue Aug 18, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Aug 18, 2026
@lakshmimsft
lakshmimsft added this pull request to the merge queue Aug 18, 2026
Merged via the queue into main with commit 3b75231 Aug 18, 2026
78 checks passed
@lakshmimsft
lakshmimsft deleted the lakshmimsft/redact-remote-template-url branch August 18, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants