Files
prowler/prowler
Lydia Vilchez 6b4950f922 refactor(azure): address CodeRabbit follow-up review comments
- verify_client certificate branch now manages the ThreadPoolExecutor
  explicitly so shutdown(wait=False) on timeout does not extend the
  30s deadline while credential.get_token is still running.
- client-secret token endpoint uses the shared
  _TOKEN_ACQUISITION_TIMEOUT_SECONDS constant instead of hardcoded 30.
- setup_session env-var certificate branch catches TypeError (raised by
  load_pem_private_key when a PEM key is password-protected and no
  password is supplied) alongside binascii.Error, OSError and friends.
- setup_session re-raises AzureNotValidCertificateContentError and
  AzureNotValidCertificatePathError before the outer except Exception
  wraps them into AzureSetUpSessionError, so callers still see the
  certificate-specific error type.
- validate_arguments error message no longer names --certificate-content
  as a CLI flag (the option only exists on the API/UI credential shape).
- Changelog fragment drops the redundant 'Add' verb per the prowler
  changelog convention.
- Test paths that need a non-existent file use tmp_path instead of
  hardcoded /tmp/ locations that could collide on shared runners.
- validate_arguments, setup_identity and verify_client docstrings
  document the new certificate parameters and typed errors.
2026-08-31 18:22:56 +02:00
..