Skip to content

Too much details are being displayed in generic error message owncompany/identityproviders (PUT) #1473

@JordanGerada3

Description

@JordanGerada3

When making a request via the owncompany/identityproviders (PUT) endpoint too much information is being reviewed which may pose a security risk.

Current Behavior

The following information is returned when throwing a generic error:

  • Internal component names
  • URLs
  • Keycloak import-config endpoint

Expected Behavior

  • Only specific information about the failure to assist in debugging.
  • No sensitive or potentially compromising information to be displayed.

Steps To Reproduce

  • Login to the Portal
  • Navigate to the IDP Management page
  • Click on the Add Identity Provider button
  • Enter necessary details till you reach the Metadata URL input box. Enter any random URL. Click on the Save Metadata button and intercept the request.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    Status

    NEW USER REQUEST

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions