Re: [Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Isuru Perera
Hi, On Fri, Jan 31, 2014 at 8:32 AM, Udara Liyanage wrote: > I'm not saying printing password is a good thing, but let's say we want to > see if the passwords are set correctly how do we check it. Remote debug is > kind of a hard. > Well, it's okay to have logs and see whether the password is s

Re: [Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Udara Liyanage
I'm not saying printing password is a good thing, but let's say we want to see if the passwords are set correctly how do we check it. Remote debug is kind of a hard. Touched, not typed. Erroneous words are a feature, not a typo. On Jan 30, 2014 11:29 PM, "Isuru Perera" wrote: > Hi, > > > On Thu,

Re: [Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Isuru Perera
Hi, On Thu, Jan 30, 2014 at 11:15 PM, Lahiru Sandaruwan wrote: > > > > On Thu, Jan 30, 2014 at 10:41 AM, Isuru Perera wrote: > >> Hi, >> >> My personal opinions: >> >> 1. Passwords should never be logged. So, we should fix the code. >> > > +1 > >> 2. INFO level logs should be enough for running

Re: [Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Isuru Perera
Hi, My personal opinions: 1. Passwords should never be logged. So, we should fix the code. 2. INFO level logs should be enough for running the servers in production. DEBUG level logs should be enabled only when we need to *debug*. I'm not sure why you say that we recommend running servers in prod

Re: [Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Lahiru Sandaruwan
On Thu, Jan 30, 2014 at 10:41 AM, Isuru Perera wrote: > Hi, > > My personal opinions: > > 1. Passwords should never be logged. So, we should fix the code. > +1 > 2. INFO level logs should be enough for running the servers in production. > DEBUG level logs should be enabled only when we need to

[Dev] Password is printed in plain text in debug logs when you add secondary userstore

2014-01-30 Thread Lahiru Sandaruwan
Hi all, I noticed $subject. AFAIK we are recommended to run servers in debug mode in production. So is $subject appropriate? Thanks. -- -- Lahiru Sandaruwan Software Engineer, Platform Technologies, WSO2 Inc., http://wso2.com lean.enterprise.middleware email: lahi...@wso2.com cell: (+94) 773 3