Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-2844

Passwords submitted REST API login method are logged by AccessLogFilter

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • 2.2.1
    • 2.0.5
    • REST API, Security
    • None
    • panda

    Description

      For example, when using the IDE plug-in, the following appears in the log (I've manually replaced my password with "MY_PASSWORD"):

      2008-07-03 10:50:12,215 INFO [http-8080-Processor17] [AccessLogFilter] ahempel http://panda.sydney.atlassian.com:8080/bamboo/api/rest/login.action?username=ahempel&password= MY_PASSWORD&os_username=ahempel&os_password=MY_PASSWORD 67902kb
      

      Attachments

        Activity

          People

            bmccoy bmccoy
            ahempel Adrian Hempel [Atlassian]
            Votes:
            1 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: