Only print Auth token when in Verbose mode#275
Open
gllebede-havok wants to merge 1 commit intomicrosoft:developfrom
Open
Only print Auth token when in Verbose mode#275gllebede-havok wants to merge 1 commit intomicrosoft:developfrom
gllebede-havok wants to merge 1 commit intomicrosoft:developfrom
Conversation
jwittner
requested changes
Sep 23, 2024
|
|
||
| Write-Verbose "Summary" | ||
| Write-Output $upmConfigs | ||
| Write-Verbose $upmConfigs |
Member
There was a problem hiding this comment.
I think we should either skip the summary or strip the tokens from the objects. Even in verbose it's not good practice.
Member
There was a problem hiding this comment.
As a note - Write-Output is like adding it to the return value. It'll only get printed if the caller doesn't capture the output. That said, I agree that I think the author was trying to print this out for the summary not return it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
It looks like the intention was to print the Auth token only when in Verbose mode, taking into account previous line.
Printing Auth PAT to console in normal mode may expose PAT to a party with malicious intent.