From d964233e56a341eff4ec16661048adbb26bd7d1e Mon Sep 17 00:00:00 2001 From: pedrooot Date: Fri, 9 Oct 2026 11:15:12 +0200 Subject: [PATCH] fix(iac): keep the clone error out of logs and responses --- prowler/providers/iac/iac_provider.py | 7 +++++-- tests/providers/iac/iac_provider_test.py | 10 ++++++++-- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/prowler/providers/iac/iac_provider.py b/prowler/providers/iac/iac_provider.py index 378fe5b8ae..96de189725 100644 --- a/prowler/providers/iac/iac_provider.py +++ b/prowler/providers/iac/iac_provider.py @@ -416,11 +416,14 @@ class IacProvider(Provider): return temporary_directory, branch_name except Exception as error: + # the authenticated URL embeds the token, and ProwlerException puts + # original_exception into its str(), which the API returns verbatim logger.critical( - f"{error.__class__.__name__}:{error.__traceback__.tb_lineno} -- {error}" + f"{error.__class__.__name__}:{error.__traceback__.tb_lineno}" ) raise IacRepositoryCloneError( - file=__file__, original_exception=error + file=__file__, + message=f"Unable to clone the repository to scan ({error.__class__.__name__})", ) from error def run(self) -> List[CheckReportIAC]: diff --git a/tests/providers/iac/iac_provider_test.py b/tests/providers/iac/iac_provider_test.py index ab8c4a563b..6d3622dc72 100644 --- a/tests/providers/iac/iac_provider_test.py +++ b/tests/providers/iac/iac_provider_test.py @@ -861,13 +861,19 @@ class TestIacProvider: lets the API report the failure as a normal task error instead of a `SystemExit` escaping the Celery worker. """ - mock_clone.side_effect = Exception("repository not found") + mock_clone.side_effect = Exception( + "https://x-access-token:SENTINEL_TOKEN@github.com/user/repo.git refused" + ) with pytest.raises(IacRepositoryCloneError) as exc_info: IacProvider(scan_repository_url="https://github.com/user/repo.git") - assert "repository not found" in str(exc_info.value) + # ProwlerException formats original_exception into its str(), and the API + # returns that, so the authenticated URL must not reach it + assert "SENTINEL_TOKEN" not in str(exc_info.value) + assert "Exception" in str(exc_info.value) assert exc_info.value.code == 21000 + assert isinstance(exc_info.value.__cause__, Exception) def test_detect_branch_name_main(self): """Test detecting 'main' branch from .git/HEAD"""