Project

General

Profile

Bug #15940

Package upload action logs whole input as Parameters

Added by Lukas Zapletal over 2 years ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Category:
Subscriptions
Target version:
Difficulty:
easy
Triaged:
Yes
Bugzilla link:
Team Backlog:
Fixed in Releases:
Found in Releases:

Description

Rails logs all incoming parameters via INFO logger by default (no opt-out).

Package upload request can be huge JSON and it does not make sense to log everything.

Rails provide parameter filters to filter out sensitive data from these (e.g. passwords), the action could perhaps use this to opt-out logging of the whole root data (_json key).

Associated revisions

Revision 59e9f514 (diff)
Added by Justin Sherrill over 2 years ago

Fixes #15940 - filter out package profile upload logs (#6264)

History

#1 Updated by Justin Sherrill over 2 years ago

  • Assignee set to Justin Sherrill
  • Legacy Backlogs Release (now unused) set to 162
  • Difficulty set to easy

#2 Updated by The Foreman Bot over 2 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/Katello/katello/pull/6264 added

#3 Updated by Brad Buckingham over 2 years ago

  • Target version set to 123

#4 Updated by Justin Sherrill over 2 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#5 Updated by Chris Duryee about 2 years ago

  • Bugzilla link set to 1429642

Also available in: Atom PDF