cinderclient displays keystone token data when --debug is used
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
python-cinderclient |
Fix Released
|
High
|
Jay Bryant |
Bug Description
When using the --debug option with cinderclient it is possible to see the username and password being used to access cinder:
bash-4.1# cinder --debug list
REQ: curl -i http://
DEBUG:cindercli
REQ: curl -i http://
Other projects have changes to resolve this issue:
The neutronclient proposal -
https:/
use 'REDACTED'
There is a novaclient patch in the gate that uses SHA1(<sha1oftoken>) -
https:/
Morgan was working on keystone.session patch -
https:/
This ML thread discusses the accepted way for handling the situation: http://
Changed in python-cinderclient: | |
importance: | Undecided → High |
assignee: | nobody → Jay Bryant (jsbryant) |
Changed in python-cinderclient: | |
status: | New → In Progress |
Changed in python-cinderclient: | |
milestone: | none → 1.3.1 |
status: | Fix Committed → Fix Released |
Update to this, the first thing that needs to be changed will be based on the changes to Nova to change output from this:
REQ: curl -i 'http:// 192.168. 122.188: 8774/v2/ 04103f5a55c847a d892958019c8b56 09/servers/ detail' -X GET -H "X-Auth-Project-Id: service" -H "User-Agent: python-novaclient" -H "Accept: application/json" -H "X-Auth-Token: MIIN8wYJKoZIhvc NAQcCoIIN5DCCDe ACAQExCTAHBgUrD gMCGjCCDEkGCSqG SIb3DQEHAaCCDDo Eggw2eyJhY2Nlc3 MiOiB7InRva2VuI jogeyJpc3N1ZWRf YXQiOiAiMjAxNC0 wNy0xNFQyMDowNz oxMy45NTIyMDIiL CAiZXhwaXJlcyI6 ICIyMDE0LTA3LTE 0VDIxOjA3OjEzWi IsICJpZCI6ICJwb GFjZWhvbGRlciIs ICJ0ZW5hbnQiOiB 7ImRlc2NyaXB0aW 9uIjogIlNlcnZpY 2UgVGVuYW50Iiwg ImVuYWJsZWQiOiB 0cnVlLCAiaWQiOi AiMDQxMDNmNWE1N WM4NDdhZDg5Mjk1 ODAxOWM4YjU2MDk iLCAibmFtZSI6IC JzZXJ2aWNlIn19L CAic2VydmljZUNh dGFsb2ciOiBbeyJ lbmRwb2ludHMiOi BbeyJhZG1pblVST CI6ICJodHRwOi8v MTkyLjE2OC4xMjI uMTg4Ojg3NzQvdj IvMDQxMDNmNWE1N WM4NDdhZDg5Mjk1 ODAxOWM4YjU2MDk iLCAicmVnaW9uIj ogIlJlZ2lvbk9uZ SIsICJpbnRlcm5h bFVSTCI6ICJodHR wOi8vMTkyLjE2OC 4xMjIuMTg4Ojg3N zQvdjIvMDQxMDNm NWE1NWM4NDdhZDg 5Mjk1ODAxOWM4Yj U2MDkiLCAiaWQiO iAiMDAxMTQ4NjA3 MWY0NGM3NTgwZjI yNzA0ZTcxYjQ2Nj UiLCAicHVibGljV VJMIjogImh0dHA6 Ly8xOTIuMTY4LjE yMi4xODg6ODc3NC 92Mi8wNDEwM2Y1Y TU1Yzg0N2FkODky OTU4MDE5YzhiNTY wOSJ9XSwgImVuZH BvaW50c19saW5rc yI6IFtdLCAidHlw ZSI6ICJjb21wdXR lIiwgIm5hbWUiOi Aibm92YSJ9LCB7I mVuZHBvaW50cyI6 IFt7ImFkbWluVVJ MIjogImh0dHA6Ly 8xOTIuMTY4LjEyM i4xODg6OTY5NiIs ICJyZWdpb24iOiA iUmVnaW9uT25lIi wgImludGVybmFsV VJMIjogImh0dHA6 Ly8xOTIuMTY4LjE yMi4xODg6OTY5Ni IsICJpZCI6ICI2Y TYxZDAzMjA1MDE0 YjQ2YjFhMjM2MTc 3ZjkwMGUxNyIsIC JwdWJsaWNVUkwiO iAiaHR0cDovLzE5 Mi4xNjguMTIyLjE 4ODo5Njk2In1dLC AiZW5kcG9pbnRzX 2xpbmtzIjogW10s ICJ0eXBlIjogIm5 ldHdvcmsiLCAibm FtZSI6ICJuZXV0c m9uIn0sIHsiZW5k cG9pbnRzIjogW3s iYWRtaW5VUkwiOi AiaHR0cDovLzE5M i4xNjguMTIyLjE4 ODo4Nzc0L3YzIiw gInJlZ2lvbiI6IC JSZWdpb25PbmUiL CAiaW50ZXJuYWxV UkwiOiAiaHR0cDo vLzE5Mi4xNjguMT IyLjE4ODo4Nzc0L 3YzIiwgImlkIjog ImExMjZiYjBlMmJ lNTQ5YWVhMGE1NT FiMmRiNmY4OTBlI iwgInB1YmxpY1VS TCI6ICJodHRwOi8 vMTkyLjE2OC4xMj IuMTg4Ojg3NzQvd jMifV0sICJlbmRw b2ludHNfbGlua3M iOiBbXSwgInR5cG UiOiAiY29tcHV0Z XYzIiwgIm5hbWUi OiAibm92YSJ9LCB 7ImVuZHBvaW50cy I6IFt7ImFkbWluV VJMIjogImh0dHA6 Ly8xOTIuMTY4LjE yMi4xODg6OTI5Mi IsICJyZWdpb24iO iAiUmVnaW9uT25l IiwgImludGVybmF sVVJMIjogImh0dH A6Ly8xOTIuMTY4L jEyMi4xODg6OTI5 MiIsICJpZCI6ICI 1NTU3YjE1NTRjZm I0NGU4OTRiYmI2M jQwNjI5NTZkMCIs ICJwdWJsaWNVUkw iOiAiaHR0cDovLz E5Mi4xNjguMTIyL jE4ODo5MjkyIn1d LCAiZW5kcG9pbnR zX2xpbmtzIjogW1 0sICJ0eXBlIjogI mltYWdlIiwgIm5h bWUiOiAiZ2xhbmN lIn0sIHsiZW5kcG 9pbnRzIjogW3siY WRtaW5VUkwiOiAi aHR0cDovLzE5Mi4 xNjguMTIyLjE4OD o4Nzc3IiwgInJlZ 2lvbiI6ICJSZWdp b25PbmUiLCAiaW5 0ZXJuYWxVUkwiOi AiaHR0cDovLzE5M i4xNjguMTIyLjE4 ODo4Nzc3IiwgIml kIjogImIxNjNhMD JhZjBhNjQ0NDA5M TdmZTI2NmZhYzMz ZmU1IiwgInB1Ymx pY1VSTCI6ICJodH RwOi8vMTkyLjE2O C4xMjIuMTg4Ojg3 NzcifV0sICJlbmR wb2ludHNfbGlua3 MiOiBbXSwgInR5c GUiOiAibWV0ZXJp bmciLCAibmFtZSI 6ICJjZWlsb21ldG VyIn0sIHsiZW5kc G9pbnRzIjogW3si YWRtaW5VUkwiOiA iaHR0cDovLzE5Mi 4xNjguMTIyLjE4O Do4Nzc2L3YxLzA0 MTAzZjVhNTVjODQ 3YWQ4OTI5NTgwMT ljOGI1NjA5IiwgI nJlZ2lvbiI6ICJS ZWdpb25PbmUiLCA iaW50ZXJuYWxVUk wiOiAiaHR0cDovL zE5Mi4xNjguMTIy LjE4ODo4Nzc2L3Y xLzA0MTAzZjVhNT VjODQ3YWQ4OTI5N TgwMTljOGI1NjA5 IiwgImlkIjogIjd mZGNmYWI2NDViZT RkOGM5NTI3MzFiM TY4ZTMyYTk5Iiwg InB1YmxpY1VSTCI 6ICJodHRwOi8vMT kyLjE2OC4xMjIuM Tg4Ojg3NzYvdjEv MDQxMDNmNWE1NWM 4NDdhZDg5Mjk1OD AxOWM4YjU2M. ..