fix(m365): remove last encrypted password appearances (#7941)

Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
Co-authored-by: Víctor Fernández Poyatos <victor@prowler.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
This commit is contained in:
Prowler Bot
2025-06-05 19:00:49 +05:45
committed by GitHub
co-authored by Hugo Pereira Brito Víctor Fernández Poyatos Pepe Fagoaga
parent 6355be4ede
commit 8831572c5f
5 changed files with 22 additions and 26 deletions
+4 -4
View File
@@ -9243,7 +9243,7 @@ components:
description: User microsoft email address.
password:
type: string
description: User encrypted password.
description: User password.
required:
- client_id
- client_secret
@@ -10488,7 +10488,7 @@ components:
description: User microsoft email address.
password:
type: string
description: User encrypted password.
description: User password.
required:
- client_id
- client_secret
@@ -10697,7 +10697,7 @@ components:
description: User microsoft email address.
password:
type: string
description: User encrypted password.
description: User password.
required:
- client_id
- client_secret
@@ -10922,7 +10922,7 @@ components:
description: User microsoft email address.
password:
type: string
description: User encrypted password.
description: User password.
required:
- client_id
- client_secret
@@ -121,7 +121,7 @@ from rest_framework_json_api import serializers
},
"password": {
"type": "string",
"description": "User encrypted password.",
"description": "User password.",
},
},
"required": [
@@ -106,9 +106,9 @@ class M365BaseException(ProwlerException):
"message": "The provided User is not valid.",
"remediation": "Check the User and ensure it is a valid user.",
},
(6025, "M365NotValidEncryptedPasswordError"): {
"message": "The provided Encrypted Password is not valid.",
"remediation": "Check the Encrypted Password and ensure it is a valid password.",
(6025, "M365NotValidPasswordError"): {
"message": "The provided Password is not valid.",
"remediation": "Check the Password and ensure it is a valid password.",
},
(6026, "M365UserNotBelongingToTenantError"): {
"message": "The provided User does not belong to the specified tenant.",
@@ -312,7 +312,7 @@ class M365NotValidUserError(M365CredentialsError):
)
class M365NotValidEncryptedPasswordError(M365CredentialsError):
class M365NotValidPasswordError(M365CredentialsError):
def __init__(self, file=None, original_exception=None, message=None):
super().__init__(
6025, file=file, original_exception=original_exception, message=message
+4 -4
View File
@@ -43,7 +43,7 @@ from prowler.providers.m365.exceptions.exceptions import (
M365NotTenantIdButClientIdAndClientSecretError,
M365NotValidClientIdError,
M365NotValidClientSecretError,
M365NotValidEncryptedPasswordError,
M365NotValidPasswordError,
M365NotValidTenantIdError,
M365NotValidUserError,
M365SetUpRegionConfigError,
@@ -296,7 +296,7 @@ class M365Provider(Provider):
client_id (str): The M365 Client ID.
client_secret (str): The M365 Client Secret.
user (str): The M365 User Account.
encrpted_password (str): The M365 Encrypted Password.
password (str): The M365 User Password.
Raises:
M365BrowserAuthNoTenantIDError: If browser authentication is enabled but the tenant ID is not found.
@@ -1032,9 +1032,9 @@ class M365Provider(Provider):
# Validate the Encrypted Password
if not password:
raise M365NotValidEncryptedPasswordError(
raise M365NotValidPasswordError(
file=os.path.basename(__file__),
message="The provided Encrypted Password is not valid.",
message="The provided Password is not valid.",
)
try:
+9 -13
View File
@@ -24,7 +24,7 @@ from prowler.providers.m365.exceptions.exceptions import (
M365NoAuthenticationMethodError,
M365NotValidClientIdError,
M365NotValidClientSecretError,
M365NotValidEncryptedPasswordError,
M365NotValidPasswordError,
M365NotValidTenantIdError,
M365NotValidUserError,
M365UserNotBelongingToTenantError,
@@ -396,14 +396,12 @@ class TestM365Provider:
with patch(
"prowler.providers.m365.m365_provider.M365Provider.validate_static_credentials"
) as mock_validate_static_credentials:
mock_validate_static_credentials.side_effect = (
M365NotValidEncryptedPasswordError(
file=os.path.basename(__file__),
message="The provided M365 Encrypted Password is not valid.",
)
mock_validate_static_credentials.side_effect = M365NotValidPasswordError(
file=os.path.basename(__file__),
message="The provided M365 Password is not valid.",
)
with pytest.raises(M365NotValidEncryptedPasswordError) as exception:
with pytest.raises(M365NotValidPasswordError) as exception:
M365Provider.test_connection(
tenant_id=str(uuid4()),
region="M365Global",
@@ -414,10 +412,8 @@ class TestM365Provider:
password=None,
)
assert exception.type == M365NotValidEncryptedPasswordError
assert "The provided M365 Encrypted Password is not valid." in str(
exception.value
)
assert exception.type == M365NotValidPasswordError
assert "The provided M365 Password is not valid." in str(exception.value)
def test_test_connection_with_httpresponseerror(self):
with patch(
@@ -588,7 +584,7 @@ class TestM365Provider:
assert "The provided User is not valid." in str(exception.value)
def test_validate_static_credentials_missing_password(self):
with pytest.raises(M365NotValidEncryptedPasswordError) as exception:
with pytest.raises(M365NotValidPasswordError) as exception:
M365Provider.validate_static_credentials(
tenant_id="12345678-1234-5678-1234-567812345678",
client_id="12345678-1234-5678-1234-567812345678",
@@ -596,7 +592,7 @@ class TestM365Provider:
user="test@example.com",
password="",
)
assert "The provided Encrypted Password is not valid." in str(exception.value)
assert "The provided Password is not valid." in str(exception.value)
def test_validate_arguments_missing_env_credentials(self):
with pytest.raises(M365MissingEnvironmentCredentialsError) as exception: