Hide token generated by "Get token" tasks #444
+7
−0
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Use the existing
ah_configuration_*_secure_logging
variables to give the possibility to hide the generated tokenAdded
no_log: "{{ ah_configuration_X_secure_logging }}"
to everyGet Token
taskCreated a new variable
ah_configuration_offline_sync_secure_logging
for theoffline_sync
roleHow should this be tested?
Set
ah_configuration_X_secure_logging
of a role which has aGet Token
task totrue
and see that the authentication token is now hidden in the output of the taskGet Token
Is there a relevant Issue open for this?
N/A
Other Relevant info, PRs, etc
The code in this repo is often used in pipelines where the job log is public.
It is a good practice to hide the token which usually have superadmin role.