Skip to content

Strip credentials in case of 400 on /v3/auth/tokens #335

Description

@drzraf

Screenshot from 2021-07-28 15-28-38

Seriously, such an exception (the one on /v3/auth/tokens should be caught to avoid displaying credentials).
In -production, they would be logged which is not much better. Such a failure should be cleaned before being thrown.

Stack


  at vendor/php-opencloud/openstack/src/Common/Error/Builder.php:128
  at OpenStack\Common\Error\Builder->httpError()
     (vendor/php-opencloud/openstack/src/Common/Transport/Middleware.php:27)
  at OpenStack\Common\Transport\Middleware::OpenStack\Common\Transport\{closure}()
     (vendor/guzzlehttp/promises/src/FulfilledPromise.php:41)
  at GuzzleHttp\Promise\FulfilledPromise::GuzzleHttp\Promise\{closure}()
     (vendor/guzzlehttp/promises/src/TaskQueue.php:48)
  at GuzzleHttp\Promise\TaskQueue->run()
     (vendor/guzzlehttp/promises/src/Promise.php:248)
  at GuzzleHttp\Promise\Promise->invokeWaitFn()
     (vendor/guzzlehttp/promises/src/Promise.php:224)
  at GuzzleHttp\Promise\Promise->waitIfPending()
     (vendor/guzzlehttp/promises/src/Promise.php:62)
  at GuzzleHttp\Promise\Promise->wait()
     (vendor/guzzlehttp/guzzle/src/Client.php:187)
  at GuzzleHttp\Client->request()
     (vendor/php-opencloud/openstack/src/Common/Api/OperatorTrait.php:119)
  at OpenStack\Common\Resource\OperatorResource->sendRequest()
     (vendor/php-opencloud/openstack/src/Common/Api/OperatorTrait.php:127)
  at OpenStack\Common\Resource\OperatorResource->execute()
     (vendor/php-opencloud/openstack/src/Identity/v3/Models/Token.php:117)
  at OpenStack\Identity\v3\Models\Token->create()
     (vendor/php-opencloud/openstack/src/Identity/v3/Service.php:74)
  at OpenStack\Identity\v3\Service->generateToken()

Activity

  1. changed the title [-]Strip OS credentials in case of 400 on /v3/auth/tokens[/-] [+]Strip credentials in case of 400 on /v3/auth/tokens[/+] on Jul 28, 2021
  2. jeroenlammerts commented on Mar 15, 2023

    @jeroenlammerts

    #259 disabling the http_errors is not working, looks like there is a custom middelware which throws the error above with credentials.

    public function httpError(RequestInterface $request, ResponseInterface $response): BadResponseError

  3. added a commit that references this issue on Feb 5, 2024
    d823be3
  4. added a commit that references this issue on Jun 19, 2024
    baa4872
  5. added a commit that references this issue on Jun 12, 2025
    7104354
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions