This Bugzilla instance is deprecated, and most Eclipse projects now use GitHub or Eclipse GitLab. Please see the deprecation plan for details.
Bug 249268 - Passwords appear in log file
Summary: Passwords appear in log file
Status: CLOSED FIXED
Alias: None
Product: z_Archived
Classification: Eclipse Foundation
Component: EPF (show other bugs)
Version: unspecified   Edit
Hardware: PC All
: P3 normal (vote)
Target Milestone: ---   Edit
Assignee: Onno van der Straaten CLA
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-01 02:58 EDT by Onno van der Straaten CLA
Modified: 2023-02-16 16:32 EST (History)
0 users

See Also:


Attachments
mylyn/context/zip (7.86 KB, application/octet-stream)
2008-10-01 15:24 EDT, Onno van der Straaten CLA
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Onno van der Straaten CLA 2008-10-01 02:58:48 EDT
1.5. RC 1

Reported by Henrik Terävä
Comment 1 Onno van der Straaten CLA 2008-10-01 05:10:03 EDT
The whole email appears in the log file. This is not the application but the Rails framework. If we remove the password from the email that solves that. Also the parameters from the sign-up are logged. This also puts the passwords in the log file.

See also
247616: Password crypted and NOT sent in a email
https://bugs.eclipse.org/bugs/show_bug.cgi?id=247616

Removed password from email and set filtering on


Comment 2 Onno van der Straaten CLA 2008-10-01 15:24:26 EDT
Created attachment 114033 [details]
mylyn/context/zip
Comment 3 Onno van der Straaten CLA 2008-10-03 06:31:58 EDT
Confirmed to work in dailybuild environment. 

Login is now:
Processing LoginController#login (for 83.87.70.69 at 2008-10-03 03:25:22) [POST]
  Session ID: 1e8b990c1bfa3389dcf2702606d64709
  Parameters: {"user"=>{"password"=>"[FILTERED]", "remember_me"=>"1", "email"=>"onno.van.der.straaten@logica.com"}, "commit"=>"Let me in!", "action"=>"login", "controller"=>"login"}
  
Lost password:
Processing LoginController#lost_password (for 83.87.70.69 at 2008-10-03 03:16:35) [POST]
  Session ID: 1e8b990c1bfa3389dcf2702606d64709
  Parameters: {"user"=>{"password_confirmation"=>"[FILTERED]", "password"=>"[FILTERED]", "email"=>"onno.van.der.straaten@logica.com"}, "commit"=>"Send new password", "action"=>"lost_password", "controller"=>"login"}
Finding user with email: onno.van.der.straaten@logica.com

Sign-up
Processing LoginController#sign_up (for 83.87.70.69 at 2008-10-03 03:15:26) [POST]
  Session ID: 1e8b990c1bfa3389dcf2702606d64709
  Parameters: {"user"=>{"name"=>"Onno", "password_confirmation"=>"[FILTERED]", "password"=>"[FILTERED]", "email"=>"onno.van.der.straaten@logica.com"}, "commit"=>"Sign me up!", "action"=>"sign_up", "controller"=>"login"}
Creating account with supplied password for onno.van.der.straaten@logica.com
Comment 4 Onno van der Straaten CLA 2010-12-02 09:55:31 EST
OK