Skip to content

Redact openid_connect secret

Hello,

OIDC secret is not redacted.

gitlab_rails['omniauth_providers'] = [
 {
   'name' => 'openid_connect',
   'label' => 'my OIDC',
   'args' => {
     'name' => 'openid_connect',
     'scope' => ['openid', 'profile', 'email'],
     'response_type' => 'code',
     'issuer' =>  'https://login.microsoftonline.com/<TENANT ID>/v2.0',
     'client_auth_method' => 'query',
     'discovery' => true,
     'uid_field' => 'oid',
     'client_options' => {
       'identifier' => 'aabbccdd-11a1-111a-a11a-aabbccddeeff',
       'secret' => 'THIS SECRET IS CURRENTLY NOT REDACTED',
       'redirect_uri' => 'https://gitlab.example.com/users/auth/openid_connect/callback'
     }
   }
 }
]

_secret string is caught in the sanitizer but not the secret string.