[ https://issues.apache.org/jira/browse/DRILL-6250?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16404625#comment-16404625 ]
ASF GitHub Bot commented on DRILL-6250: --------------------------------------- Github user arina-ielchiieva commented on the issue: https://github.com/apache/drill/pull/1174 +1 > Sqlline start command with password appears in the sqlline.log > -------------------------------------------------------------- > > Key: DRILL-6250 > URL: https://issues.apache.org/jira/browse/DRILL-6250 > Project: Apache Drill > Issue Type: Bug > Affects Versions: 1.13.0 > Reporter: Anton Gozhiy > Assignee: Volodymyr Tkach > Priority: Major > Labels: ready-to-commit > Fix For: 1.14.0 > > > *Prerequisites:* > *1.* Log level is set to "all" in the conf/logback.xml: > {code:xml} > <logger name="org.apache.drill" additivity="false"> > <level value="all" /> > <appender-ref ref="FILE" /> > </logger> > {code} > *2.* PLAIN authentication mechanism is configured: > {code:java} > security.user.auth: { > enabled: true, > packages += "org.apache.drill.exec.rpc.user.security", > impl: "pam", > pam_profiles: [ "sudo", "login" ] > } > {code} > *Steps:* > *1.* Start the drillbits > *2.* Connect by sqlline: > {noformat} > /opt/mapr/drill/drill-1.13.0/bin/sqlline -u "jdbc:drill:zk=node1:5181;" -n > user1 -p 1234 > {noformat} > *3.* Use check the sqlline logs: > {noformat} > tail -F log/sqlline.log|grep 1234 -a5 -b5 > {noformat} > *Expected result:* Logs shouldn't contain clear-text passwords > *Actual result:* The logs contain the sqlline start command with password: > {noformat} > # system properties > 35333- "java" : { > 35352- # system properties > 35384: "command" : "sqlline.SqlLine -d > org.apache.drill.jdbc.Driver --maxWidth=10000 --color=true -u > jdbc:drill:zk=node1:5181; -n user1 -p 1234", > 35535- # system properties > 35567- "launcher" : "SUN_STANDARD" > 35607- } > {noformat} -- This message was sent by Atlassian JIRA (v7.6.3#76005)