Skip to content

Redact SAS tokens and lowercase account keys in AzureBlockBlobBackend.as_uri - #10620

Merged
auvipy merged 3 commits into
celery:mainfrom
Dev-next-gen:fix/azureblockblob-redact-sas
Sep 13, 2026
Merged

auvipy merged 3 commits into
celery:mainfrom
Dev-next-gen:fix/azureblockblob-redact-sas

Conversation

@Dev-next-gen

Copy link
Copy Markdown
Contributor

Note: Before submitting this pull request, please review our contributing
guidelines
.

Description

While reading AzureBlockBlobBackend.as_uri() I noticed it only masks a connection string part that starts with the exact text AccountKey=. The Azure SDK accepts two other forms that carry a secret, and both came out in clear.

The first is a SAS connection string (BlobEndpoint=...;SharedAccessSignature=sv=...&sig=...), which BlobServiceClient.from_connection_string() accepts as is. The second is the same key in a different case: the SDK upper-cases keys before reading them (parse_connection_str in azure-storage-blob 12.30.1), so accountkey=... authenticates fine but is not matched by startswith('AccountKey=').

I checked this against azure-storage-blob 12.30.1 with a fake token. On main:

>>> AzureBlockBlobBackend(app=app, url="azureblockblob://BlobEndpoint=https://acct.blob.core.windows.net/;SharedAccessSignature=sv=2022-11-02&sig=SECRETSIG%3D").as_uri()
'azureblockblob://BlobEndpoint=https://acct.blob.core.windows.net/;SharedAccessSignature=sv=2022-11-02&sig=SECRETSIG%3D'
>>> AzureBlockBlobBackend(app=app, url="azureblockblob://AccountName=acct;accountkey=c2VjcmV0a2V5").as_uri()
'azureblockblob://AccountName=acct;accountkey=c2VjcmV0a2V5'

as_uri() is what the worker banner prints on its results: line (celery/apps/worker.py), so the token ends up in startup logs.

The fix compares each key case-insensitively against AccountKey and SharedAccessSignature and keeps the key as the user wrote it, so the existing AccountKey=** output is unchanged. include_password=True still returns the full string.

I added two tests next to the existing as_uri ones. Both fail on main with an assertion error and pass with the change, and the whole t/unit/backends/test_azureblockblob.py passes (22 tests). flake8 is clean on both files.

AI tools used

Dev-next-gen and others added 2 commits September 13, 2026 05:53
….as_uri

as_uri() only masked a part that starts with the exact text "AccountKey=".
Azure also accepts a SharedAccessSignature in the connection string and
matches keys case-insensitively, so a SAS token or an "accountkey=" was
printed in clear, for example in the results line of the worker banner.
@auvipy
auvipy self-requested a review September 13, 2026 04:25
@auvipy auvipy added this to the 5.7.x milestone Sep 13, 2026
@codecov

codecov Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.07%. Comparing base (d98d411) to head (58d0004).

Additional details and impacted files
@@           Coverage Diff           @@
##             main   #10620   +/-   ##
=======================================
  Coverage   89.07%   89.07%           
=======================================
  Files         153      153           
  Lines       20139    20143    +4     
  Branches     2371     2373    +2     
=======================================
+ Hits        17938    17942    +4     
  Misses       1896     1896           
  Partials      305      305           
Flag Coverage Δ
unittests 89.05% <100.00%> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

@auvipy auvipy modified the milestones: 5.7.x, 5.7.0 Sep 13, 2026
@auvipy
auvipy merged commit c05238b into celery:main Sep 13, 2026
1 of 3 checks passed
ac2-d2c-c47-4ad4608af pushed a commit to ac2-d2c-c47-4ad4608af/celery that referenced this pull request Sep 21, 2026
….as_uri (celery#10620)

as_uri() only masked a part that starts with the exact text "AccountKey=".
Azure also accepts a SharedAccessSignature in the connection string and
matches keys case-insensitively, so a SAS token or an "accountkey=" was
printed in clear, for example in the results line of the worker banner.

Co-authored-by: Asif Saif Uddin {"Auvi":"অভি"} <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants