mirror of
https://github.com/ansible-middleware/keycloak.git
synced 2026-08-02 04:44:48 +00:00
fix(keycloak_quarkus): avoid leaking maven provider password in logs
The Validate providers / Download custom providers via http / Copy local providers tasks loop over all providers and print the item (including maven.password) in cleartext, even for skipped iterations. Add the same conditional no_log the maven download/copy tasks already use so entries carrying a secret are censored while url/local providers stay visible. Refs ansible-middleware/keycloak#362 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -123,6 +123,7 @@
|
||||
fail_msg: >
|
||||
Providers definition incorrect; `id` and one of `spi`, `url`, `local_path`, or `maven` are mandatory. `key` and `value` are mandatory for each property
|
||||
loop: "{{ keycloak_quarkus_providers }}"
|
||||
no_log: "{{ item.maven.password is defined and item.maven.password | length > 0 | default(false) }}"
|
||||
|
||||
- name: "Validate policies"
|
||||
ansible.builtin.assert:
|
||||
|
||||
Reference in New Issue
Block a user