Bug 744206

Summary: User REST API call to retrieve user info returns hashed password
Product: [Retired] Pulp Reporter: Jay Dobies <jason.dobies>
Component: user-experienceAssignee: Jason Connor <jconnor>
Status: CLOSED CURRENTRELEASE QA Contact: Preethi Thomas <pthomas>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 1.0.0CC: mmccune, skarmark
Target Milestone: ---Keywords: Triaged
Target Release: Sprint 29   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-02-24 20:14:52 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Jay Dobies 2011-10-07 13:30:08 UTC
At least it's hashed, but this is still really ugly that we return it.

In [4]: pic.GET('/users/admin/')
Out[4]: 
(200,
 {u'_id': u'7384d011-35f7-485b-913f-5bc0b8680c63',
  u'_ns': u'users',
  u'id': u'7384d011-35f7-485b-913f-5bc0b8680c63',
  u'login': u'admin',
  u'name': None,
  u'password': u'64pJHslFvWA=,szkMUZ7Kz4PCTIWfvaq6oKTbzmkmHeJGDsKKHx+c6UM=',
  u'roles': [u'super-users']})

Comment 1 Jason Connor 2011-10-10 17:32:39 UTC
removed the field from all the returned user instances.

Comment 2 Jeff Ortel 2011-10-13 00:49:25 UTC
build: 0.238

Comment 3 Preethi Thomas 2011-10-13 18:50:08 UTC
[root@preethi ~]# rpm -q pulp
pulp-0.0.238-1.fc15.noarch
[root@preethi ~]# 
[root@preethi ~]# 
[root@preethi ~]# curl -k -u admin:admin --request GET  https://localhost/pulp/api/users/admin/
{"_id": "8e91315d-0765-4f79-8ad4-bd3c76d6a125", "name": null, "roles": ["super-users"], "_ns": "users", "login": "admin", "id": "8e91315d-0765-4f79-8ad4-bd3c76d6a125"}[root@preethi ~]#

Comment 4 Preethi Thomas 2012-02-24 20:14:52 UTC
Pulp v1.0 is released
Closed Current Release.

Comment 5 Preethi Thomas 2012-02-24 20:19:42 UTC
Pulp v1.0 is released.