Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Doesn't hide Azure Storage Account Keys when shown #45

Open
Zhaph opened this issue Sep 27, 2024 · 0 comments
Open

Doesn't hide Azure Storage Account Keys when shown #45

Zhaph opened this issue Sep 27, 2024 · 0 comments

Comments

@Zhaph
Copy link

Zhaph commented Sep 27, 2024

With the plugin enabled, navigate to an Azure Storage Account in the Azure Portal, expand "Security + networking" and open "Access keys".

The pre-obfusticated keys and connectionstrings are correctly (excessively) blurred.

Press "Show" to enable the "Copy to clipboard" feature or similar and the actual key is shown, unredacted:

Example of Storage Account Access keys, showing the default, dotted text redacted, but the actual key is perfectly visible

Similar issue occurs when generating a Shared access signature - elements that change after initial load are not redacted:
Shared Access Signature screen after "Generate SAS and connection string" pressed.

As these are usually truncated in the text boxes, it's probably not too much of an issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant