fix: logs can leak sensitive information.. - #64337
Conversation
Signed-off-by: Akhil <akhil@e.email>
0a9c618 to
0da138d
Compare
icewind1991
left a comment
There was a problem hiding this comment.
Cannot reproduce the original issue, but the change is good either way.
Currently this info is duplicated in the logs
|
/backport to stable35 |
|
/backport to stable34 |
|
/backport to stable33 |
|
@icewind1991 maybe this is not about basic auth but about apache auth like But agree this really makes sense anyways! |
|
Hello there, We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process. Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6 Thank you for contributing to Nextcloud and we hope to hear from you soon! (If you believe you should not receive this message, you can add yourself to the blocklist.) |
Summary
After the commit 121973d336e, certain types of logger calls are outputting sensitive data like credentials in the error logs
server/apps/dav/lib/Connector/Sabre/Auth.php
Line 121 in f740a01
This PR addresses this security issue
TODO
Checklist
3. to review, feature component)stable32)AI (if applicable)