Page MenuHomePhabricator

Censor response bodies from Mercurial error messages

Authored by epriestley on Mar 26 2015, 4:50 PM.



Ref T6755. In Git and Subversion, running git clone or svn checkout does not echo the response body.

In Mercurial, it does. Censor it from the output of hg pull and hg clone. This prevents an attacker from:

  • Creating a Mercurial remote repository with URI; and
  • reading the secrets out of the error message after the clone fails.
Test Plan

Set a Mercurial remote URI to a non-Mercurial repository, ran repository update, saw censored error message.

Diff Detail

rP Phabricator
Automatic diff as part of commit; lint not applicable.
Automatic diff as part of commit; unit tests not applicable.