fix: redact env var values in agent debug manifest endpoint (#26904)

This commit is contained in:
Jon Ayers
2026-07-01 10:46:35 -05:00
committed by GitHub
parent 679eb00ec4
commit b33ff2d851
2 changed files with 55 additions and 1 deletions
+23 -1
View File
@@ -2291,12 +2291,34 @@ func (a *agent) HandleHTTPDebugManifest(w http.ResponseWriter, r *http.Request)
return
}
// Redact env values. This endpoint is unauthenticated on loopback,
// reachable by any process regardless of Unix user. Keys are preserved
// so operators can still see which variables are configured.
debugManifest := *sdkManifest
if len(sdkManifest.EnvironmentVariables) > 0 {
envs := make(map[string]string, len(sdkManifest.EnvironmentVariables))
for k, v := range sdkManifest.EnvironmentVariables {
// Preserve empty values, which carry no secret, matching
// sanitizeEnv in support/support.go.
if v == "" {
envs[k] = v
continue
}
envs[k] = redactedManifestEnvValue
}
debugManifest.EnvironmentVariables = envs
}
w.WriteHeader(http.StatusOK)
if err := json.NewEncoder(w).Encode(sdkManifest); err != nil {
if err := json.NewEncoder(w).Encode(debugManifest); err != nil {
a.logger.Error(a.hardCtx, "write debug manifest", slog.Error(err))
}
}
// redactedManifestEnvValue matches the marker used by sanitizeEnv in
// support/support.go so a support bundle and this endpoint agree.
const redactedManifestEnvValue = "***REDACTED***"
func (a *agent) HTTPDebug() http.Handler {
r := chi.NewRouter()