Skip to content

Data source username and password are visible in the changelog #13729

@mtbutler07

Description

@mtbutler07

NetBox version

v3.6.1

Feature type

Change to existing functionality

Proposed functionality

When creating a new data source (git) in NetBox with username/password fields populated, a changelog entry is created that contains the diff of the username/password in plain text.

Screenshot from 2023-09-08 13-30-35

This is not ideal for a number of reasons, the primary one being that it exposes credentials to other users that can view the NetBox changelog.

I'm proposing that the the username and password fields be masked or excluded entirely from the changelog entry to prevent exposing credentials.

Use case

It would prevent exposing credentials to other users that are able to view the changelog.

Database changes

No response

External dependencies

No response

Metadata

Metadata

Assignees

Labels

status: acceptedThis issue has been accepted for implementationtype: featureIntroduction of new functionality to the application

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions