Setting `host` in `Configuration` causes credentials to be sent in the clear
Maintainer antworten meist innerhalb von 2 Tagen
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 35/100
Rechercherichtung
Der Bericht nennt Configuration(host=...), ApiClient(configuration) und MonitorsApi.list_monitors(), aber keine Quelldatei oder keinen Testpfad. Beginne damit nachzuverfolgen, wie der konfigurierte Host das Request-Schema auswählt, und vergleiche es mit dem Pfad für den Standard-Host. Erledigt ist es, wenn explizit konfigurierte Hosts standardmäßig TLS verwenden und Zugangsdaten niemals über die anfängliche HTTP-Anfrage gesendet werden; füge einen Regressionstest für den reproduzierten Fall hinzu.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Describe the bug
Setting host in the Configuration ctor causes credentials to be sent in the clear.
To Reproduce
Take this example:
import os
from datadog_api_client import ApiClient, Configuration
from datadog_api_client.v1.api.monitors_api import MonitorsApi
configuration = Configuration(
host=os.environ['DATADOG_HOST'],
)
configuration.api_key["apiKeyAuth"] = os.environ['DATADOG_API_KEY']
configuration.api_key["appKeyAuth"] = os.environ['DATADOG_APP_KEY']
configuration.debug = True
with ApiClient(configuration) as api_client:
monitors_api = MonitorsApi(api_client)
monitors = monitors_api.list_monitors()
print('{} monitors'.format(len(monitors)))
You can tell from the debug output that we're not doing TLS:
send: b'GET /api/v1/monitor HTTP/1.1\r\nHost: <subdomain>.datadoghq.com\r\nAccept: application/json\r\n<snip>\r\n\r\n'
reply: 'HTTP/1.1 308 Permanent Redirect\r\n'
header: Date: Fri, 08 Dec 2023 23:22:03 GMT
header: Content-Length: 0
header: Connection: keep-alive
header: location: https://<subdomain>.datadoghq.com/api/v1/monitor
header: x-content-type-options: nosniff
header: strict-transport-security: max-age=31536000; includeSubDomains; preload
send: b'GET /api/v1/monitor HTTP/1.1\r\nHost: <subdomain>.datadoghq.com\r\nAccept: application/json\r\n<snip>\r\n\r\n'
reply: 'HTTP/1.1 200 OK\r\n'
header: Date: Fri, 08 Dec 2023 23:22:03 GMT
header: Content-Type: application/json
header: Transfer-Encoding: chunked
header: Connection: keep-alive
header: etag: W/"721e351f3b20293a0d2bc1301301df83"
header: x-frame-options: SAMEORIGIN
header: content-security-policy: frame-ancestors 'self'; report-uri https://logs.browser-intake-datadoghq.com/api/v2/logs?dd-api-key=pube4f163c23bbf91c16b8f57f56af9fc58&dd-evp-origin=content-security-policy&ddsource=csp-report&ddtags=site%3Adatadoghq.com
header: vary: Accept-Encoding
header: content-encoding: gzip
header: x-ratelimit-limit: 1000
header: x-ratelimit-period: 10
header: x-ratelimit-remaining: 999
header: x-ratelimit-reset: 7
header: x-ratelimit-name: get_all_monitors
header: x-content-type-options: nosniff
header: strict-transport-security: max-age=31536000; includeSubDomains; preload
240 monitors
That double request is pretty clearly an HTTP→HTTPS redirect. Wireshark confirms as much. Oddly, whatever the default for host is doesn't do this, but I didn't realize until much later that setting host isn't required, see the Additional Context section. Initially, I was under the impression that configuration of what DD tenant I was was required.
Expected behavior
TLS is enabled by default … and ideally only switch off very explicitly. Certainly overriding things like hostname don't then also remove TLS, in addition…
Environment and Versions (please complete the following information):
A clear and precise description of your setup:
- version for this project in use: 2.19.0
- services, libraries, languages and tools list and versions: the minimal example above
Additional context
I ended up setting host almost by accident. Initially, I was getting 403 Forbidden from the API, and wasn't sure why; I was using the "Getting Started" example, and setting an API key. It turns out DD requires both an API key and an "app" key (the README does note this, but I missed that in my first pass), which is somewhat unusual. So, AFAICT, I wasn't authenticated, but since the wrong HTTP status was getting returned, that never clicked, and I tried other things (such as configuring my host) prior to returning to the what-if of "perhaps it is, indeed, authn?"
I'm not clear on why one can construct a DD client without (full) credentials without error in the first place.
- Vorherrschende Sprache
- Python
- Sterne
- 167
- Forks
- 55
- Ø Merge
- 3 T. 17 Std.
- Gemergte PRs (30 T.)
- 80
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus DataDog/datadog-api-client-python
-
Python 3.13/3.14 SyntaxWarning in v1 LogsPipelinesApi docstringEvtl. vergeben @Mirochill hat das vor 142 Tagen übernommen. Offenstale
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 72/100
DataDog/datadog-api-client-python#3535 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 2 Tagen
-
kind/bug stale
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 66/100
DataDog/datadog-api-client-python#3717 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 2 Tagen
-
kind/bug stale
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 75/100
DataDog/datadog-api-client-python#3656 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 2 Tagen
-
kind/bug stale
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 38/100
DataDog/datadog-api-client-python#3120 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 2 Tagen
-
stale
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
DataDog/datadog-api-client-python#2986 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 2 Tagen
Alle Issues in DataDog/datadog-api-client-python
Ähnliche Issues
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
topoteretes/cognee#5647 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 62/100
Sendspin/sendspin-python-cli#291 ·
Maintainer antworten meist innerhalb von 6 Tagen
-
Assertion-shape guard fails on development: vacuous recorded-iteration assertion in the assetLinks batch_get helper testEvtl. vergeben Ein verknüpfter Pull Request ist offen oder bereits gemergt. Offenbug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
awslabs/visual-asset-management-system#414 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug v1 v2
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
modelcontextprotocol/python-sdk#3670 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
aicell-lab/bioengine#232 ·
Maintainer antworten meist innerhalb von 1 Tag