trove exist events send out admin password in the event string

Bug #1218028 reported by Saurabh Surana
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OpenStack DBaaS (Trove)
Fix Released
Critical
Justin Hopper

Bug Description

The way we construct admin context for generating exists event, the password for the admin user is set in the auth_token field which is sent out in the exist events.

Changed in trove:
assignee: nobody → Justin Hopper (justin-hopper)
Changed in trove:
status: New → In Progress
Changed in trove:
milestone: none → havana-rc1
information type: Private Security → Public
Changed in trove:
importance: Undecided → Critical
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to trove (master)

Reviewed: https://review.openstack.org/46138
Committed: http://github.com/openstack/trove/commit/52d892fe546535f88915b2a8582d482af7bae4e1
Submitter: Jenkins
Branch: master

commit 52d892fe546535f88915b2a8582d482af7bae4e1
Author: justin-hopper <email address hidden>
Date: Wed Sep 11 14:09:49 2013 -0700

    Fixed Admin Auth Token in Notification

       before notifications are sent - admin auth token is
       set to None to ensure it is not logged

    Fixes: Bug 1218028
    Change-Id: Ib53244f14d8e2e8c77e0bb67e2156e2eb0165866

Changed in trove:
status: In Progress → Fix Committed
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to trove (milestone-proposed)

Fix proposed to branch: milestone-proposed
Review: https://review.openstack.org/46602

Changed in trove:
status: Fix Committed → Fix Released
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to trove (milestone-proposed)

Reviewed: https://review.openstack.org/46602
Committed: http://github.com/openstack/trove/commit/59a12fe3cffd6d3af49c1dc25128fde99543b563
Submitter: Jenkins
Branch: milestone-proposed

commit 59a12fe3cffd6d3af49c1dc25128fde99543b563
Author: justin-hopper <email address hidden>
Date: Wed Sep 11 14:09:49 2013 -0700

    Fixed Admin Auth Token in Notification

       before notifications are sent - admin auth token is
       set to None to ensure it is not logged

    Fixes: Bug 1218028
    Change-Id: Ib53244f14d8e2e8c77e0bb67e2156e2eb0165866
    (cherry picked from commit 52d892fe546535f88915b2a8582d482af7bae4e1)

Thierry Carrez (ttx)
Changed in trove:
milestone: havana-rc1 → 2013.2
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.