[Security/Low] D365 check_connection leaks server response body into logs
Open-source Excel-native EPM and consolidation for SAP & Dynamics
Brought to you by:
konsolid-at
Originally created by: pyy3
Severity: Low · Type: security
The D365 connector's connection check returns the raw server response body in its error message, which is surfaced in Airbyte's UI/logs and may include echoed request details.
source-d365-fno/source_d365_fno/auth.py (~line 66):
except requests.exceptions.HTTPError as e:
return False, f"Authentication failed: {e.response.status_code} {e.response.text}"
except Exception as e:
return False, f"Authentication error: {str(e)}"
Azure AD error responses can echo request metadata; surfacing e.response.text risks leaking identifiers into logs. Minor, but easy to tighten. (Note: TLS verification itself is fine — requests verifies by default and no verify=False is set.)
except Exception to requests.RequestException.
Originally posted by: pyy3
Fixed in [#34] (merged to
main).Related
Tickets:
#34Ticket changed by: pyy3