-
Notifications
You must be signed in to change notification settings - Fork 36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug]: Failed to sanitize DB2 connection string #614
Labels
Comments
Hey Weslley, thanks for the detailed report. We'll take a look at this. |
basti1302
added a commit
that referenced
this issue
Sep 19, 2022
Improves the regex to redact the password by not expecting a subsequent semicolon character after the PWD parameter. fixes #614
basti1302
added a commit
that referenced
this issue
Sep 19, 2022
Improves the regex to redact the password by not expecting a subsequent semicolon character after the PWD parameter. fixes #614
basti1302
added a commit
that referenced
this issue
Sep 19, 2022
Improves the regex to redact the password by not expecting a subsequent semicolon character after the PWD parameter. fixes #614
A fix will be released with the next release (probably tomorrow). |
The fix has landed in version 2.8.0. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Problem Description
The sanitizeConnectionStr function regex doesn't match a connection string where PWD is the last parameter included and does not contain the semicolon. Package: tracingUtil.js
This causes string sanitize not to work.
Short, Self Contained Example
Connection string: "DATABASE=MY_DATABASE;HOSTNAME=localhost;PORT=50000;PROTOCOL=TCPIP;UID=my_user;PWD=123456"
In this case the regex contained in the code does not match, as there is no semicolon.
data:image/s3,"s3://crabby-images/99cda/99cda56028f9b71021148c2776b8ca60ed4792d1" alt="image"
PWD=.*?(?=;)
I suggest using the regex like this:
data:image/s3,"s3://crabby-images/e9058/e9058623bb2112a02d9290bab4a73c6faf927b49" alt="image"
PWD=.*?(?=;|$)
Node.js Version
Node.js v16.14.0
package.json
package-lock.json
The text was updated successfully, but these errors were encountered: