[tahoe-lafs-trac-stream] [tahoe-lafs] #2037: cloud/S3 backend fails to redact ProductToken and UserToken from S3 error messages

tahoe-lafs trac at tahoe-lafs.org
Fri Jul 26 01:49:40 UTC 2013


#2037: cloud/S3 backend fails to redact ProductToken and UserToken from S3 error
messages
-------------------------+-------------------------------------------------
     Reporter:  daira    |      Owner:  daira
         Type:  defect   |     Status:  assigned
     Priority:  normal   |  Milestone:  soon
    Component:  unknown  |    Version:  1.9.0-s3branch
   Resolution:           |   Keywords:  security logging s3 cloud-backend
Launchpad Bug:           |  ticket999-S3-backend
-------------------------+-------------------------------------------------

Comment (by daira):

 Note that the {{{s3secret}}} key is not leaked by this problem, so the
 impact is quite limited. However, the new end-to-end monitoring has a
 greater chance of revealing error messages to the public monitoring list.

-- 
Ticket URL: <https://tahoe-lafs.org/trac/tahoe-lafs/ticket/2037#comment:2>
tahoe-lafs <https://tahoe-lafs.org>
secure decentralized storage


More information about the tahoe-lafs-trac-stream mailing list