Trust id is not hidden in logs
Bug #1472331 reported by
Ekaterina Chernova
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Murano |
Fix Released
|
High
|
Lin Yang | ||
Kilo |
Fix Committed
|
High
|
Kirill Zaitsev |
Bug Description
When murano creates trustes and operates with data, contains it, the value of trust is not hidden:
"SystemData": {"TrustId": "d5f1261a5a4f48
Need to use *** like it's done with token
Changed in murano: | |
milestone: | 2014.2.3 → liberty-2 |
tags: | added: security |
tags: | added: low-hanging-fruit |
Changed in murano: | |
assignee: | nobody → Lin Yang (lin-a-yang) |
Changed in murano: | |
status: | Confirmed → In Progress |
tags: | added: kilo-backport-potential |
tags: | added: in-stable-kilo |
Changed in murano: | |
status: | Fix Committed → Fix Released |
Changed in murano: | |
milestone: | liberty-2 → 1.0.0 |
Changed in murano: | |
milestone: | 1.0.0 → 1.0.1 |
To post a comment you must log in.
Reviewed: https:/ /review. openstack. org/199407 /git.openstack. org/cgit/ openstack/ murano/ commit/ ?id=8933765635d 01c2bcc3f6679e0 ab8c0b9e448a3b
Committed: https:/
Submitter: Jenkins
Branch: master
commit 8933765635d01c2 bcc3f6679e0ab8c 0b9e448a3b
Author: Lin Yang <email address hidden>
Date: Wed Jul 8 13:53:15 2015 +0800
Hide TrustId in log to tighten up security
Current the value of TrustId is showed in plaintext in log when murano creates
trustes and operates with data. So add 'trustid' in token_sanitizer to hide it
like token and pass.
Closes-Bug: #1472331
Change-Id: I1e9ea8298a7ffd 9aa742cf73fada6 9db3a734712