Don't leak credentials in debug_info
No need to dump Gmail OAuth client_secret, refresh_token, and access_token in the debug ZIP in plaintext.
This commit is contained in:
@@ -326,7 +326,9 @@ class ConfigSQL(object):
|
||||
def to_dict(self):
|
||||
storage = {}
|
||||
for k, v in self.__dict__.items():
|
||||
if k[0] != '_' and not k.endswith("_e") and not k == "cli" and 'api' not in k.lower():
|
||||
if k[0] != '_' and not k.endswith("_e") and not k == "cli" \
|
||||
and 'api' not in k.lower() and 'token' not in k.lower() \
|
||||
and 'secret' not in k.lower()
|
||||
storage[k] = v
|
||||
return storage
|
||||
|
||||
|
||||
Reference in New Issue
Block a user