Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-13595

Mask Webhook secret Key

    XMLWordPrintable

Details

    Description

      While configuring webhooks in bitbucket, we have the option to provide a secret key that is not masked, and hence the plain text secret key is visible in audit logs, kindly mask the secret key 

      Steps to reproduce 

      1. Configure webhook in Bitbucket server
      2. When the hook is created,modified we see the secret key in Plan text in the audit logs.

       

      Work Around : 

      Currently we only have one work around to turn off Local configuration and administration log level in audit settings, which also disables other useful login events which is not desirable.  

       

      Attachments

        Activity

          People

            8f36004e07e8 Milly Wilson
            14e68c70fbc3 Neeraj Upadhyay
            Votes:
            3 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: