Skip to content

Keep Tool Configuration credentials out of the edit form - #15624

Open
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:fix/tool-config-credential-render
Open

Keep Tool Configuration credentials out of the edit form#15624
svader0 wants to merge 1 commit into
DefectDojo:bugfixfrom
svader0:fix/tool-config-credential-render

Conversation

@svader0

@svader0 svader0 commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Hardening / consistency improvement to the Tool Configuration edit form. Stored credential values are no longer sent back to the browser, matching what the Django admin form for the same model already does, and an omitted value on save is treated as unchanged rather than cleared. That second part also fixes a small data-loss bug: saving the form today without re-entering the credential wipes it.

Adds a regression test. No functional change for correctly-permissioned users.

The edit view decrypted the stored password and ssh key on GET and the form
bound all three credential fields with their values, so anyone permitted to
edit a tool configuration could read the credentials it holds. The Django
admin form for the same model already masks these fields.

Stop sending the stored values to the browser and treat a blank submission as
"unchanged" on save, which also fixes clearing a credential by saving the form
without re-entering it. The stored value is only reused while the URL is
unchanged, so a credential is never paired with a destination supplied in the
same request.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant