Aditya Sharma created OFBIZ-9310:
------------------------------------

             Summary: On setting verbose true, UtilHttp.getParameterMap() 
method prints username and password in logs
                 Key: OFBIZ-9310
                 URL: https://issues.apache.org/jira/browse/OFBIZ-9310
             Project: OFBiz
          Issue Type: Bug
            Reporter: Aditya Sharma
            Assignee: Aditya Sharma


In UtilHttp.getParameterMap(HttpServletRequest request, Set<? extends String> 
nameSet, Boolean onlyIncludeOrSkip) method, following line of code prints 
username and password in logs when verbose is set to true.


if (Debug.verboseOn()) {
            Debug.logVerbose("Made Request Parameter Map with [" + 
paramMap.size() + "] Entries", module);
            Debug.logVerbose("Request Parameter Map Entries: " + 
System.getProperty("line.separator") + UtilMisc.printMap(paramMap), module);
        }




--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to