Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[$250] Always mask auth tokens when exporting Onyx state #47995

Closed
TMisiukiewicz opened this issue Aug 26, 2024 · 16 comments
Closed

[$250] Always mask auth tokens when exporting Onyx state #47995

TMisiukiewicz opened this issue Aug 26, 2024 · 16 comments
Assignees
Labels
AutoAssignerNewDotQuality Used to assign quality issues to engineers Daily KSv2 External Added to denote the issue can be worked on by a contributor Reviewing Has a PR in review

Comments

@TMisiukiewicz
Copy link
Contributor

TMisiukiewicz commented Aug 26, 2024

Problem

When exporting the Onyx state from the Troubleshoot section, sensitive information such as authToken and encryptedAuthToken are not masked by default. These tokens remain exposed until the "Mask fragile user data" option is explicitly enabled. This could lead to a security vulnerability, as anyone with access to the exported state file could potentially view or misuse these tokens.

Solution

To mitigate this risk, it should automatically mask authToken and encryptedAuthToken regardless of whether the "Mask fragile user data" option is enabled.

Upwork Automation - Do Not Edit
  • Upwork Job URL: https://www.upwork.com/jobs/~021838166767638673695
  • Upwork Job ID: 1838166767638673695
  • Last Price Increase: 2024-09-23
Issue OwnerCurrent Issue Owner: @
Issue OwnerCurrent Issue Owner: @muttmuure
@TMisiukiewicz
Copy link
Contributor Author

cc @mountiny

@melvin-bot melvin-bot bot added Reviewing Has a PR in review Weekly KSv2 labels Aug 26, 2024
@mountiny mountiny added the AutoAssignerNewDotQuality Used to assign quality issues to engineers label Aug 26, 2024
Copy link

melvin-bot bot commented Aug 26, 2024

Current assignee @mountiny is eligible for the AutoAssignerNewDotQuality assigner, not assigning anyone new.

Copy link

melvin-bot bot commented Aug 26, 2024

📣 @kyy23! 📣
Hey, it seems we don’t have your contributor details yet! You'll only have to do this once, and this is how we'll hire you on Upwork.
Please follow these steps:

  1. Make sure you've read and understood the contributing guidelines.
  2. Get the email address used to login to your Expensify account. If you don't already have an Expensify account, create one here. If you have multiple accounts (e.g. one for testing), please use your main account email.
  3. Get the link to your Upwork profile. It's necessary because we only pay via Upwork. You can access it by logging in, and then clicking on your name. It'll look like this. If you don't already have an account, sign up for one here.
  4. Copy the format below and paste it in a comment on this issue. Replace the placeholder text with your actual details.
    Screen Shot 2022-11-16 at 4 42 54 PM
    Format:
Contributor details
Your Expensify account email: <REPLACE EMAIL HERE>
Upwork Profile Link: <REPLACE LINK HERE>

@goldman727
Copy link

Hello, TMisiukiewicz
I can mask authToken and encryptedAuthToken automatically. please let me know if you allow me to do it.

@muttmuure
Copy link
Contributor

Merged!

@github-project-automation github-project-automation bot moved this from MEDIUM to Done in [#whatsnext] #quality Sep 18, 2024
@hoangzinh
Copy link
Contributor

@muttmuure it appears that we haven't processed payment for this issue. Can you double check it? Thank you

@muttmuure muttmuure reopened this Sep 23, 2024
@muttmuure muttmuure self-assigned this Sep 23, 2024
@muttmuure muttmuure added the External Added to denote the issue can be worked on by a contributor label Sep 23, 2024
@melvin-bot melvin-bot bot changed the title Always mask auth tokens when exporting Onyx state [$250] Always mask auth tokens when exporting Onyx state Sep 23, 2024
Copy link

melvin-bot bot commented Sep 23, 2024

Job added to Upwork: https://www.upwork.com/jobs/~021838166767638673695

@melvin-bot melvin-bot bot added the Help Wanted Apply this label when an issue is open to proposals by contributors label Sep 23, 2024
Copy link

melvin-bot bot commented Sep 23, 2024

Current assignee @hoangzinh is eligible for the External assigner, not assigning anyone new.

@melvin-bot melvin-bot bot added Daily KSv2 and removed Weekly KSv2 labels Sep 23, 2024
@muttmuure muttmuure removed the Help Wanted Apply this label when an issue is open to proposals by contributors label Sep 23, 2024
@muttmuure
Copy link
Contributor

Invited

@hoangzinh
Copy link
Contributor

@muttmuure I haven't received the Upwork offer yet. Can you check it again? Thank you

@muttmuure
Copy link
Contributor

Can you share your upwork profile?

@hoangzinh
Copy link
Contributor

Sent you in Slack @muttmuure

@muttmuure
Copy link
Contributor

Offer sent

@hoangzinh
Copy link
Contributor

Accepted. Thanks @muttmuure

@hoangzinh
Copy link
Contributor

hoangzinh commented Oct 10, 2024

cc @muttmuure for payment so we can close this issue ^

@muttmuure
Copy link
Contributor

Paid!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
AutoAssignerNewDotQuality Used to assign quality issues to engineers Daily KSv2 External Added to denote the issue can be worked on by a contributor Reviewing Has a PR in review
Projects
Status: Done
Development

No branches or pull requests

5 participants