Skip to content

[PAPP-38452] Add opt-in sensitive response headers - #71

Merged
phantom-jacob merged 3 commits into
mainfrom
sodle/papp-38452-sensitive-header-opt-in
Sep 16, 2026
Merged

phantom-jacob merged 3 commits into
mainfrom
sodle/papp-38452-sensitive-header-opt-in

Conversation

@sodle-splunk

Copy link
Copy Markdown
Contributor

Summary

  • add a per-action expose_sensitive_response_headers option, disabled by default
  • return sensitive response headers only when the option is explicitly enabled
  • document the option and add regression coverage

Validation

  • python3 -m unittest discover -s tests -v
  • ruff check http_connector.py tests/test_response_headers.py
  • ruff format --check http_connector.py tests/test_response_headers.py
  • jq empty http.json

Fixes PAPP-38452

@github-actions

github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Merging this PR will release 4.0.2 with the following release notes:

4.0.2 (2026-09-16)

Bug Fixes

  • add opt-in sensitive response headers (59413cd)

Connector release changes

  • Added an action-level opt-in to include Authorization, Cookie, Proxy-Authenticate, Set-Cookie, and Set-Cookie2 response headers in action results. The option is disabled by default; when enabled, the values persist with the container and remain available to users with container-view access.

@phantom-jacob
phantom-jacob merged commit a4aae8c into main Sep 16, 2026
10 of 19 checks passed
@phantom-jacob
phantom-jacob deleted the sodle/papp-38452-sensitive-header-opt-in branch September 16, 2026 18:01
@splunk-soar-semantic-release

Copy link
Copy Markdown

🎉 This PR is included in version 4.0.2 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants