Redact secrets in command and cluster API context - #145
Merged
Shashank Mittal (shashank-iitbhu) merged 3 commits intoSep 29, 2026
Merged
Conversation
Keep password, private_key, and similar fields in responses but replace their values so GET /commands and /clusters no longer leak credentials.
Shashank Mittal (shashank-iitbhu)
marked this pull request as ready for review
September 22, 2026 08:01
Collaborator
|
Shashank Mittal (@shashank-iitbhu) can we simply add json tag "-" which will skip those attributes from marshalling into output bytes? |
Contributor
Author
We can do this on the complete context blob, but not just on passwords. |
Keep the API table focused and document redaction next to the other credential-handling guidance.
Yash Shrivastava (alephys26)
approved these changes
Sep 25, 2026
prasadlohakpure
approved these changes
Sep 29, 2026
Shashank Mittal (shashank-iitbhu)
deleted the
cursor/redact-sensitive-api-context
branch
September 29, 2026 06:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
GET
/api/v1/commandsand/api/v1/clusters(and the matching single-object endpoints) return objectcontextas JSON. Command and cluster configs can store credentials there (password, Snowflakeprivate_keypath, authtokenpath), so callers could read them from the API.This always redacts
password,private_key, andtokenon JSON marshal (REDACTED) while leaving the real values in memory, in DB persistence (Context.String()), and for plugins (Context.Unmarshal). Additional key names can be configured without a code change.Configuration
The three built-in keys are always protected. Extra names can be configured globally in Heimdall YAML; matching is case-insensitive and applies recursively to command, cluster, and job contexts:
A restart is required after changing it.
Test plan
Auth header is
X-Heimdall-User. Rebuild is required for the Go change.Seed a command and cluster with secrets:
GET (no auth header required):
Expected:
{ "nested": { "endpoint": "https://example", "private_key": "REDACTED" }, "password": "REDACTED", "username": "shelf-user" }{ "endpoint": "http://ranger.local", "password": "REDACTED", "private_key": "REDACTED", "token": "REDACTED", "username": "admin" }Pass: keys still present, values are
"REDACTED", non-secret fields unchanged.go test ./...