[ 
https://issues.apache.org/jira/browse/CAMEL-24425?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on CAMEL-24425 started by Andrea Cosentino.
------------------------------------------------
> camel-azure-storage-blob - sasToken is not marked as a secret
> -------------------------------------------------------------
>
>                 Key: CAMEL-24425
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24425
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-azure
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> BlobConfiguration.sasToken carries a bare @UriParam:
> {code:java}
> @UriParam
> private String sasToken;
> {code}
> A SAS token is a credential: it embeds the signature that grants access for 
> its validity window. Because the option is not marked, it is not masked by 
> the metadata-driven masking layers, and "sastoken" does not appear in the 
> generated SensitiveUtils keyword list, so it is not redacted where URI 
> sanitising is keyword-based either.
> camel-azure-storage-datalake already marks the equivalent option 
> (sasSignature).
> Proposal: annotate sasToken with secret = true and regenerate the component 
> metadata, which also adds the keyword to the generated SensitiveUtils list. 
> Note that adding or changing a @UriParam regenerates the catalog and both DSL 
> mirrors, so those files need committing with the change.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to