jenkins
jenkins copied to clipboard
Hide potentially sensitive values (system properties and environment variables) by default
Pages like /systemInfo
in Jenkins show potentially sensitive information to users entitled to view them. To prevent unintentionally revealing that information to shoulder surfers or when screensharing, this PR proposes to hide the values in the tables by default, adding buttons to reveal individual items or all of them.
This is not a security fix, but a security related enhancement.
TODO:
- [ ] Figure out how to overlap the individual reveal button and the text in a way compatible with localization. Right now, I just add a negative margin of fixed width.
Proposed changelog entries
- Hide values in tables showing potentially sensitive system properties and environment variables by default.
Proposed upgrade guidelines
N/A
Submitter checklist
- [ ] (If applicable) Jira issue is well described
- [ ] Changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developer, depending on the change) and are in the imperative mood. Examples
- Fill-in the
Proposed changelog entries
section only if there are breaking changes or other changes which may require extra steps from users during the upgrade
- Fill-in the
- [ ] Appropriate autotests or explanation to why this change has no tests
- [ ] New public classes, fields, and methods are annotated with
@Restricted
or have@since TODO
Javadoc, as appropriate. - [ ] New deprecations are annotated with
@Deprecated(since = "TODO")
or@Deprecated(forRemoval = true, since = "TODO")
if applicable. - [ ] For dependency updates: links to external changelogs and, if possible, full diffs
Desired reviewers
@mention
Maintainer checklist
Before the changes are marked as ready-for-merge
:
- [ ] There are at least 2 approvals for the pull request and no outstanding requests for change
- [ ] Conversations in the pull request are over OR it is explicit that a reviewer does not block the change
- [ ] Changelog entries in the PR title and/or
Proposed changelog entries
are accurate, human-readable, and in the imperative mood - [ ] Proper changelog labels are set so that the changelog can be generated automatically
- [ ] If the change needs additional upgrade steps from users,
upgrade-guide-needed
label is set and there is aProposed upgrade guidelines
section in the PR title. (example) - [ ] If it would make sense to backport the change to LTS, a Jira issue must exist, be a Bug or Improvement, and be labeled as
lts-candidate
to be considered (see query).
@NotMyFault Thanks! Any suggestions how I can resolve the TODO issue?
@NotMyFault Thanks! Any suggestions how I can resolve the TODO issue?
I have no specific pointers in mind at the moment, sorry 😢
TODO:
- [ ] Figure out how to overlap the individual reveal button and the text in a way compatible with localization. Right now, I just add a negative margin of fixed width.
Might be possible with CSS Grid - https://mastery.games/post/overlapping-grid-items/
@janfaracik Thanks, that seems to work! WDYT?
Looks weird, there seems to be something broken with jenkins-link--with-icon
:
data:image/s3,"s3://crabby-images/4fcee/4fceeef029a6e29d1bb4b658b71a733720635744" alt="Screenshot 2022-07-22 at 22 51 29"
The grid stuff doesn't work well if you have a bunch of path variables set, e.g.:
I have some WIP here which I'll pick back up later on: https://github.com/daniel-beck/jenkins/pull/9
https://github.com/daniel-beck/jenkins/pull/9 is functional now and looks quite good I think, there's a couple of CSS issues to improve in that one too described in the description
I'm happy with https://github.com/daniel-beck/jenkins/pull/9 now if you want to take a look :)
The value itself should probably not be a button, because that makes copying impossible, no?
The value itself should probably not be a button, because that makes copying impossible, no?
Copying works fine:
Copying works fine:
Huh? Then I had a bad time earlier.
You have to drag from outside of the button on the right side.
Please take a moment and address the merge conflicts of your pull request. Thanks!
/label ready-for-merge
This PR is now ready for merge, after ~24 hours, we will merge it if there's no negative feedback.
Thanks!
@timja Copy & paste of values is completely broken in Firefox. Selecting all text on the page and copying it does not copy a single value even if all are shown. Could you look into that, or consider reverting this?
@timja Copy & paste of values is completely broken in Firefox. Selecting all text on the page and copying it does not copy a single value even if all are shown. Could you look into that, or consider reverting this?
Looking
Reproduced, interesting, selecting all in chrome does get all values whereas in firefox it's not selected.
Investigating