mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
- verify_client certificate branch now manages the ThreadPoolExecutor explicitly so shutdown(wait=False) on timeout does not extend the 30s deadline while credential.get_token is still running. - client-secret token endpoint uses the shared _TOKEN_ACQUISITION_TIMEOUT_SECONDS constant instead of hardcoded 30. - setup_session env-var certificate branch catches TypeError (raised by load_pem_private_key when a PEM key is password-protected and no password is supplied) alongside binascii.Error, OSError and friends. - setup_session re-raises AzureNotValidCertificateContentError and AzureNotValidCertificatePathError before the outer except Exception wraps them into AzureSetUpSessionError, so callers still see the certificate-specific error type. - validate_arguments error message no longer names --certificate-content as a CLI flag (the option only exists on the API/UI credential shape). - Changelog fragment drops the redundant 'Add' verb per the prowler changelog convention. - Test paths that need a non-existent file use tmp_path instead of hardcoded /tmp/ locations that could collide on shared runners. - validate_arguments, setup_identity and verify_client docstrings document the new certificate parameters and typed errors.