Project

General

Profile

Actions

Bug #19044

closed

Do not send username into logs with every request

Added by Lukas Zapletal about 7 years ago. Updated about 7 years ago.

Status:
Rejected
Priority:
Normal
Category:
Security
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

From the security standpoint, this is unnecessary exposal of sensitive data. We should log database ID instead, it is still possible to pair these with usernames when needed.

We also expose this during login in Parameters Rails INFO log message, this patch will fix that as well.


Related issues 1 (0 open1 closed)

Related to Foreman - Feature #18949: Include information about current user when logginClosedIvan Necas03/17/2017Actions
Actions

Also available in: Atom PDF