[virt-tools-list] [PATCH virt-viewer v3] Do not print password in the debug log

Christophe Fergeau cfergeau at redhat.com
Tue Feb 7 16:23:15 UTC 2017


Acked-by: Christophe Fergeau <cfergeau at redhat.com>

On Tue, Jan 17, 2017 at 06:42:51PM +0100, Pavel Grunt wrote:
> Do not show a length since it is sensitive info as well.
> 
> Resolves: rhbz#1410030
> ---
>  src/virt-viewer.c | 11 ++++++++++-
>  1 file changed, 10 insertions(+), 1 deletion(-)
> 
> diff --git a/src/virt-viewer.c b/src/virt-viewer.c
> index 1121146..1f99552 100644
> --- a/src/virt-viewer.c
> +++ b/src/virt-viewer.c
> @@ -928,6 +928,11 @@ virt_viewer_auth_libvirt_credentials(virConnectCredentialPtr cred,
>      }
>  
>      for (i = 0 ; i < ncred ; i++) {
> +        const char *cred_type_to_str[] = {
> +            [VIR_CRED_USERNAME] = "Identity to act as",
> +            [VIR_CRED_AUTHNAME] = "Identify to authorize as",
> +            [VIR_CRED_PASSPHRASE] = "Passphrase secret",
> +        };
>          switch (cred[i].type) {
>          case VIR_CRED_AUTHNAME:
>          case VIR_CRED_USERNAME:
> @@ -936,7 +941,11 @@ virt_viewer_auth_libvirt_credentials(virConnectCredentialPtr cred,
>                  cred[i].resultlen = strlen(cred[i].result);
>              else
>                  cred[i].resultlen = 0;
> -            g_debug("Got '%s' %d %d", cred[i].result, cred[i].resultlen, cred[i].type);
> +            g_debug("Got %s '%s' %d",
> +                    cred_type_to_str[cred[i].type],
> +                    /* hide password */
> +                    (cred[i].type == VIR_CRED_PASSPHRASE) ? "*****" : cred[i].result,
> +                    cred[i].type);
>              break;
>          }
>      }
> -- 
> 2.11.0
> 
> _______________________________________________
> virt-tools-list mailing list
> virt-tools-list at redhat.com
> https://www.redhat.com/mailman/listinfo/virt-tools-list
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/virt-tools-list/attachments/20170207/bf1591e1/attachment.sig>


More information about the virt-tools-list mailing list