Bug 1692763 - [Kubevirt-Foreman] auth token shown in the production log
Summary: [Kubevirt-Foreman] auth token shown in the production log
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Satellite
Classification: Red Hat
Component: Compute Resources - CNV
Version: 6.6.0
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: 6.6.0
Assignee: Shira Maximov
QA Contact: Lukáš Hellebrandt
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-03-26 11:47 UTC by Vatsal Parekh
Modified: 2019-10-22 19:48 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-10-22 19:48:30 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Foreman Issue Tracker 26454 0 Normal Closed [Kubevirt-Foreman] auth token shown in the production log 2020-03-10 11:00:06 UTC
Github masayag foreman_kubevirt pull 44 0 None None None 2020-03-10 11:00:06 UTC

Description Vatsal Parekh 2019-03-26 11:47:52 UTC
Description of problem:
Production log contains the auth token used for communicating with CNV

Version-Release number of selected component (if applicable):
master of the plugin

How reproducible:


Steps to Reproduce:
1.Add a CNV compute resource
2.Token is printed in the logs
3.

Actual results:
Prints the auth token in the logs

Expected results:
Should not print, or show a encrypted one in the logs

Additional info:

Comment 3 Shira Maximov 2019-03-26 13:06:22 UTC
Created redmine issue https://projects.theforeman.org/issues/26454 from this bug

Comment 4 Vatsal Parekh 2019-04-12 06:58:22 UTC
This seems working on latest nightly Foreman + plugin master

Comment 9 Lukáš Hellebrandt 2019-07-31 10:43:53 UTC
Verified with Sat 6.6 snap 13.

Used the reproducer from OP. The log now shows '"token"=>"[FILTERED]"'.

Comment 10 Bryan Kearney 2019-10-22 19:48:30 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2019:3172


Note You need to log in before you can comment on or make changes to this bug.