Re: [PATCH virt-viewer v3] Do not print password in the debug log

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Acked-by: Christophe Fergeau <cfergeau@xxxxxxxxxx>

On Tue, Jan 17, 2017 at 06:42:51PM +0100, Pavel Grunt wrote:
> Do not show a length since it is sensitive info as well.
> 
> Resolves: rhbz#1410030
> ---
>  src/virt-viewer.c | 11 ++++++++++-
>  1 file changed, 10 insertions(+), 1 deletion(-)
> 
> diff --git a/src/virt-viewer.c b/src/virt-viewer.c
> index 1121146..1f99552 100644
> --- a/src/virt-viewer.c
> +++ b/src/virt-viewer.c
> @@ -928,6 +928,11 @@ virt_viewer_auth_libvirt_credentials(virConnectCredentialPtr cred,
>      }
>  
>      for (i = 0 ; i < ncred ; i++) {
> +        const char *cred_type_to_str[] = {
> +            [VIR_CRED_USERNAME] = "Identity to act as",
> +            [VIR_CRED_AUTHNAME] = "Identify to authorize as",
> +            [VIR_CRED_PASSPHRASE] = "Passphrase secret",
> +        };
>          switch (cred[i].type) {
>          case VIR_CRED_AUTHNAME:
>          case VIR_CRED_USERNAME:
> @@ -936,7 +941,11 @@ virt_viewer_auth_libvirt_credentials(virConnectCredentialPtr cred,
>                  cred[i].resultlen = strlen(cred[i].result);
>              else
>                  cred[i].resultlen = 0;
> -            g_debug("Got '%s' %d %d", cred[i].result, cred[i].resultlen, cred[i].type);
> +            g_debug("Got %s '%s' %d",
> +                    cred_type_to_str[cred[i].type],
> +                    /* hide password */
> +                    (cred[i].type == VIR_CRED_PASSPHRASE) ? "*****" : cred[i].result,
> +                    cred[i].type);
>              break;
>          }
>      }
> -- 
> 2.11.0
> 
> _______________________________________________
> virt-tools-list mailing list
> virt-tools-list@xxxxxxxxxx
> https://www.redhat.com/mailman/listinfo/virt-tools-list

Attachment: signature.asc
Description: PGP signature

_______________________________________________
virt-tools-list mailing list
virt-tools-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/virt-tools-list

[Index of Archives]     [Linux Virtualization]     [KVM Development]     [CentOS Virtualization]     [Netdev]     [Ethernet Bridging]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Bugtraq]     [Yosemite Forum]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux Admin]     [Samba]     [Video 4 Linux]

  Powered by Linux