Andor Molnar created ZOOKEEPER-5082:
---------------------------------------

             Summary: Remove special characters from username in audit logs
                 Key: ZOOKEEPER-5082
                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5082
             Project: ZooKeeper
          Issue Type: Bug
          Components: server
    Affects Versions: 3.9.5, 3.10.0
            Reporter: Andor Molnar
            Assignee: Andor Molnar


Follow up on ZOOKEEPER-3979 which hasn't implemented sanitization of the 
username input before logging it, hence the original log forgery issue hasn't 
been resolved.

Something similar to what has been done in EnsembleAuthenticationProvider in 
ZOOKEEPER-5058 would be preferable.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to