Skip to content

docs(kiota): document scrubbing custom sensitive headers on redirects - #172

Open
Treicysg wants to merge 2 commits into
MicrosoftDocs:mainfrom
Treicysg:add/ScrubSensitiveHeadersOnRedirect
Open

docs(kiota): document scrubbing custom sensitive headers on redirects#172
Treicysg wants to merge 2 commits into
MicrosoftDocs:mainfrom
Treicysg:add/ScrubSensitiveHeadersOnRedirect

Conversation

@Treicysg

@Treicysg Treicysg commented Jul 23, 2026

Copy link
Copy Markdown

Addresses a documentation gap identified during an MSRC-escalated security review of the redirect handler.

By default, the redirect handler only removes the standard  Authorization ,  Cookie , and  Proxy-Authorization  headers on cross-origin redirects. Custom credential headers (for example, API keys) aren't removed automatically — scrubbing them is the consumer's responsibility via the  ScrubSensitiveHeaders  callback. This documents that behavior with .NET and Python examples.

@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit da19d02:

⚠️ Validation status: warnings

File Status Preview URL Details
OpenAPI/kiota/middleware.md ⚠️Warning Details

OpenAPI/kiota/middleware.md

  • Line 179, Column 1: [Warning: invalid-tab-group - See documentation] Tab group with different tab id set.

For more details, please refer to the build report.

Note: Your PR may contain errors or warnings or suggestions unrelated to the files you changed. This happens when external dependencies like GitHub alias, Microsoft alias, cross repo links are updated. Please use these instructions to resolve them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 491d68b0-7a24-4232-8f74-20c999805600
@learn-build-service-prod

Copy link
Copy Markdown
Contributor

Learn Build status updates of commit ea7328a:

✅ Validation status: passed

File Status Preview URL Details
OpenAPI/kiota/middleware.md ✅Succeeded

For more details, please refer to the build report.

@Treicysg
Treicysg marked this pull request as ready for review July 27, 2026 23:44
@Treicysg
Treicysg requested a review from a team as a code owner July 27, 2026 23:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant