Karate DSL report serialization exposes karate-config.js secrets despite showConfig flag
0 reputation · 05 May 2022, 05:02 UTC
Configuration leakage in HTML reports
Karate merges karate-config.js and environment-specific variants at startup, then serializes the full configuration object into the default HTML and JUnit reports. The 1.x release introduced an undocumented karate.configure('report', { showConfig: false }) option intended to suppress this output, but the flag does not consistently redact nested objects or values injected via Java interop from secret managers.
Constraints and uncertainty
The flag's behavior varies across Karate patch versions and is not covered in the official documentation. Parallel execution forks additional JVMs that each re-load configuration, increasing the chance that a secret appears in at least one report fragment. CI/CD pipelines that archive build artifacts therefore risk publishing API keys, database URLs, or service-account tokens even when the flag is set.
Goal
Determine a reliable, version-stable method to prevent any configuration secret from appearing in published test reports without disabling reporting entirely.
- Does the
showConfig: falseflag reliably redact nested objects and Java-interop values in Karate 1.4.x? - Which report hooks or custom listeners can strip sensitive keys before the HTML is written?
- Is there a supported pattern for injecting secrets at runtime that avoids the configuration object altogether?