代码之家  ›  专栏  ›  技术社区  ›  node_saini

Jenkins管道脚本中的字符串插值安全吗?

  •  0
  • node_saini  · 技术社区  · 5 年前

    here . 下面是我的脚本代码的一部分,它使用用户名和密码进入一个平台以获取身份验证令牌。

    ...
    ...
       environment{
          CRED = credentials("my_cred")
       }
    ...
    ...
       sh'''
       token = $(curl --fail -H "Content-Type:application/json" -X POST https://google.com -d 
       \'{"username":"'"$CRED_USR"'","password":"'"$CRED_PSW"'"}\') 
       '''
       //prints in console '{"username":"*****","password":"*****"}'
    ...
    ...
    

    如果我只是通过下面,那么它就不起作用了。我认为在发送之前,尸体需要经过细线处理。

    "username":CRED_USR,"password":CRED_PSW
    or
    "username":'$CRED_USR',"password":'$CRED_PSW'
    

    这是可行的,但安全吗?

    "username":"'$CRED_USR'","password":"'$CRED_PSW'" 
    // prints in console '{"username":"*****","password":"*****"}'
    

    有人能让我知道我的代码是否安全吗?如果没有,请告诉我正确的方法。

    0 回复  |  直到 5 年前
        1
  •  0
  •   daggett    5 年前

    这是不安全的,因为当您在groovy级别插入密码时,它可能出现在日志中,并且有权访问日志的人可以看到密码。

    environment{
       CRED_USR = ...
       CRED_PSW = ...
    }
    ...
    
    sh '''
        curl ... '{"username":"$CRED_USR","password":"$CRED_PSW"}' ... 
    '''