Skip to content

Conversation

@katymccl
Copy link
Contributor

@katymccl katymccl commented Jul 26, 2025

Obfuscate api keys, connection strings, subscription id, resource group name, resource name in recordings. This is in response to an MSRC flagged vulnerability


This checklist is used to make sure that common guidelines for a pull request are followed.

Related command

General Guidelines

  • Have you run azdev style <YOUR_EXT> locally? (pip install azdev required)
  • Have you run python scripts/ci/test_index.py -q locally? (pip install wheel==0.30.0 required)
  • My extension version conforms to the Extension version schema

For new extensions:

About Extension Publish

There is a pipeline to automatically build, upload and publish extension wheels.
Once your pull request is merged into main branch, a new pull request will be created to update src/index.json automatically.
You only need to update the version information in file setup.py and historical information in file HISTORY.rst in your PR but do not modify src/index.json.

Obfuscate api keys, connection strings, subscription id, resource group name, resource name in recordings.
Copilot AI review requested due to automatic review settings July 26, 2025 00:30
@azure-client-tools-bot-prd
Copy link

azure-client-tools-bot-prd bot commented Jul 26, 2025

️✔️Azure CLI Extensions Breaking Change Test
️✔️Non Breaking Changes

@azure-client-tools-bot-prd
Copy link

Hi @katymccl,
Please write the description of changes which can be perceived by customers into HISTORY.rst.
If you want to release a new extension version, please update the version in setup.py as well.

@yonzhan
Copy link
Collaborator

yonzhan commented Jul 26, 2025

Thank you for your contribution! We will review the pull request and get back to you soon.

@github-actions
Copy link

The git hooks are available for azure-cli and azure-cli-extensions repos. They could help you run required checks before creating the PR.

Please sync the latest code with latest dev branch (for azure-cli) or main branch (for azure-cli-extensions).
After that please run the following commands to enable git hooks:

pip install azdev --upgrade
azdev setup -c <your azure-cli repo path> -r <your azure-cli-extensions repo path>

@microsoft-github-policy-service microsoft-github-policy-service bot added the Auto-Assign Auto assign by bot label Jul 26, 2025
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds comprehensive data obfuscation to the Quantum extension's end-to-end test recordings to prevent sensitive information from being checked into the repository. The changes enhance security by automatically redacting API keys, connection strings, subscription IDs, resource group names, and other sensitive quantum workspace data from test recording files.

Key Changes

  • Added new PowerShell functions to obfuscate API keys and quantum workspace sensitive data
  • Integrated the new obfuscation functions into the existing test recording cleanup process
  • Extended the existing SAS token obfuscation with additional security measures

@github-actions
Copy link

Hi @katymccl

Release Suggestions

Module: quantum

  • Please log updates into to src/quantum/HISTORY.rst
  • Update VERSION to 1.0.0b7 in src/quantum/setup.py

Notes

@yonzhan yonzhan requested a review from kairu-ms July 26, 2025 04:09
@yonzhan yonzhan requested a review from jsntcy July 26, 2025 04:09
@katymccl
Copy link
Contributor Author

/azp run

@azure-pipelines
Copy link

Commenter does not have sufficient privileges for PR 9004 in repo Azure/azure-cli-extensions

@yonzhan
Copy link
Collaborator

yonzhan commented Jul 31, 2025

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@katymccl
Copy link
Contributor Author

@yonzhan , @kairu-ms could you please help review and help me get this merged? this is just an update to our tests recordings in response to an information disclosure icm.

@kairu-ms
Copy link
Contributor

kairu-ms commented Aug 6, 2025

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 2 pipeline(s).

@katymccl
Copy link
Contributor Author

katymccl commented Aug 6, 2025

@jsntcy can you please review this?

@katymccl
Copy link
Contributor Author

katymccl commented Aug 8, 2025

I don't have permissions to merge this; @kairu-ms can you please merge this pr?

@kairu-ms kairu-ms merged commit c9b9648 into Azure:main Aug 10, 2025
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Auto-Assign Auto assign by bot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants