redact new password from rotation errors

This commit is contained in:
x032205
2025-10-30 02:51:27 -04:00
parent 1853544b99
commit 129b566844
@@ -41,7 +41,10 @@ export interface SqlResourceConnection {
* *
* @returns Promise to be resolved with the new credentials * @returns Promise to be resolved with the new credentials
*/ */
rotateCredentials: (currentCredentials: TSqlAccountCredentials) => Promise<TSqlAccountCredentials>; rotateCredentials: (
currentCredentials: TSqlAccountCredentials,
newPassword: string
) => Promise<TSqlAccountCredentials>;
/** /**
* Close the connection. * Close the connection.
@@ -113,8 +116,7 @@ const makeSqlConnection = (
}); });
} }
}, },
rotateCredentials: async (currentCredentials) => { rotateCredentials: async (currentCredentials, newPassword) => {
const newPassword = alphaNumericNanoId(32);
// Note: The generated random password is not really going to make SQL Injection possible. // Note: The generated random password is not really going to make SQL Injection possible.
// The reason we are not using parameters binding is that the "ALTER USER" syntax is DDL, // The reason we are not using parameters binding is that the "ALTER USER" syntax is DDL,
// parameters binding is not supported. But just in case if the this code got copied // parameters binding is not supported. But just in case if the this code got copied
@@ -295,6 +297,7 @@ export const sqlResourceFactory: TPamResourceFactory<TSqlResourceConnectionDetai
rotationAccountCredentials, rotationAccountCredentials,
currentCredentials currentCredentials
) => { ) => {
const newPassword = alphaNumericNanoId(32);
try { try {
return await executeWithGateway( return await executeWithGateway(
{ {
@@ -305,7 +308,7 @@ export const sqlResourceFactory: TPamResourceFactory<TSqlResourceConnectionDetai
password: rotationAccountCredentials.password password: rotationAccountCredentials.password
}, },
gatewayV2Service, gatewayV2Service,
(client) => client.rotateCredentials(currentCredentials) (client) => client.rotateCredentials(currentCredentials, newPassword)
); );
} catch (error) { } catch (error) {
if (error instanceof BadRequestError) { if (error instanceof BadRequestError) {
@@ -328,8 +331,10 @@ export const sqlResourceFactory: TPamResourceFactory<TSqlResourceConnectionDetai
} }
} }
const sanitizedErrorMessage = ((error as Error).message || String(error)).replaceAll(newPassword, "REDACTED");
throw new BadRequestError({ throw new BadRequestError({
message: `Unable to rotate account credentials for ${resourceType}: ${(error as Error).message || String(error)}` message: `Unable to rotate account credentials for ${resourceType}: ${sanitizedErrorMessage}`
}); });
} }
}; };