Menu ▾ ▴

#27 [Security/Low] D365 check_connection leaks server response body into logs

closed
nobody
None
2026-06-13
2026-06-12
Anonymous
No

Originally created by: pyy3

Severity: Low · Type: security

Summary

The D365 connector's connection check returns the raw server response body in its error message, which is surfaced in Airbyte's UI/logs and may include echoed request details.

Location

source-d365-fno/source_d365_fno/auth.py (~line 66):

except requests.exceptions.HTTPError as e:
    return False, f"Authentication failed: {e.response.status_code} {e.response.text}"
except Exception as e:
    return False, f"Authentication error: {str(e)}"

Impact

Azure AD error responses can echo request metadata; surfacing e.response.text risks leaking identifiers into logs. Minor, but easy to tighten. (Note: TLS verification itself is fine — requests verifies by default and no verify=False is set.)

Suggested fix

  • Return only the status code and a generic message to the user/UI; log the detailed body server-side at debug level.
  • Narrow the bare except Exception to requests.RequestException.

Related

Tickets: #34

Discussion

  • Anonymous

    Anonymous - 2026-06-13

    Originally posted by: pyy3

    Fixed in [#34] (merged to main).

     

    Related

    Tickets: #34

  • Anonymous

    Anonymous - 2026-06-13

    Ticket changed by: pyy3

    • status: open --> closed
     

Log in to post a comment.