如何在Artifact Registry Gradle插件中屏蔽访问令牌?
Google Artifact Registry Gradle插件(v2.2.5)日志泄露访问令牌问题
使用版本为2.2.5的Gradle插件com.google.cloud.artifactregistry.gradle-plugin时,发现即使将Gradle日志级别设置为info,访问令牌仍会被明文记录到日志中。但Maven扩展artifactregistry-maven-wagon不存在这个问题。
日志示例:
2025-09-12T12:02:14.4440672Z -------------- REQUEST -------------- 2025-09-12T12:02:14.4441450Z POST https://sts.googleapis.com/v1/token 2025-09-12T12:02:14.4441959Z Accept-Encoding: gzip 2025-09-12T12:02:14.4442378Z User-Agent: Google-HTTP-Java-Client/1.46.3 (gzip) 2025-09-12T12:02:14.4443234Z x-goog-api-client: gl-java/21.0.8 auth/1.33.1 google-byoid-sdk source/url sa-impersonation/true config-lifetime/false 2025-09-12T12:02:14.4444150Z Content-Type: application/x-www-form-urlencoded; charset=UTF-8 2025-09-12T12:02:14.4444715Z Content-Length: 2518 2025-09-12T12:02:14.4445011Z 2025-09-12T12:02:14.4446753Z curl -v --compressed -X POST -H 'Accept-Encoding: gzip' -H 'User-Agent: Google-HTTP-Java-Client/1.46.3 (gzip)' -H 'x-goog-api-client: gl-java/21.0.8 auth/1.33.1 google-byoid-sdk source/url sa-impersonation/true config-lifetime/false' -H 'Content-Type: application/x-www-form-urlencoded; charset=UTF-8' -d '@-' -- 'https://sts.googleapis.com/v1/token' << $$$ 2025-09-12T12:02:14.4448701Z Total: 2,518 bytes 2025-09-12T12:02:14.4519769Z grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Atoken-exchange&subject_token_type=urn%3Aietf%3Aparams%3Aoauth%3Atoken-type%3Ajwt&subject_token=*** 2025-09-12T12:02:14.4520895Z -------------- RESPONSE -------------- 2025-09-12T12:02:14.4521871Z HTTP/1.1 200 OK 2025-09-12T12:02:14.4522224Z X-Frame-Options: SAMEORIGIN 2025-09-12T12:02:14.4522617Z Transfer-Encoding: chunked 2025-09-12T12:02:14.4523009Z Server: scaffolding on HTTPServer2 2025-09-12T12:02:14.4523418Z X-Content-Type-Options: nosniff 2025-09-12T12:02:14.4523810Z Content-Encoding: gzip 2025-09-12T12:02:14.4524198Z Vary: Origin 2025-09-12T12:02:14.4524535Z Vary: X-Origin 2025-09-12T12:02:14.4524856Z Vary: Referer 2025-09-12T12:02:14.4525171Z X-XSS-Protection: 0 2025-09-12T12:02:14.4525521Z Date: Fri, 12 Sep 2025 12:02:14 GMT 2025-09-12T12:02:14.4525969Z Content-Type: application/json; charset=UTF-8 2025-09-12T12:02:14.4526307Z 2025-09-12T12:02:14.4526446Z Total: 1,561 bytes 👇 👇 👇 👇 👇 👇 👇 👇 👇 👇 👇 👇 2025-09-12T12:02:14.4526757Z { 2025-09-12T12:02:14.4539542Z "access_token": "REAL_TOKEN_SHOWN_HERE", 2025-09-12T12:02:14.4552431Z "issued_token_type": "urn:ietf:params:oauth:token-type:access_token", 2025-09-12T12:02:14.4553002Z "token_type": "Bearer", 2025-09-12T12:02:14.4553379Z "expires_in": 298 2025-09-12T12:02:14.4553691Z }
复现步骤:
build.gradle配置示例:
[...] plugins { [...] id 'maven-publish' id 'com.google.cloud.artifactregistry.gradle-plugin' version '2.2.5' } allprojects { [...] apply plugin: 'maven-publish' apply plugin: 'com.google.cloud.artifactregistry.gradle-plugin' }
- 执行命令:
./gradlew clean build -xtest --refresh-dependencies --info
内容的提问来源于stack exchange,提问作者Angelo
相关产品推荐
相关产品推荐

