Comment 5 for bug 1638978

Revision history for this message
Morgan Fainberg (mdrnstm) wrote :

I also want to point out the red hat bug is public, which means this bug should be made public.

I would prefer not to carry a copy of the mask utils from oslo and lean on the consumers of keystoneauth to pass a logger that does the masking... however, I wouldn't block the fix to carry a copy of the mask_password code.

So, tl;dr:

* Lets make this public and get the fix(es) developed and submitted to gerrit instead of under an embargo (since red hat bug is public)

* Lets evaluate the options (carry a copy of mask_password or provide clear documentation on how to mask sensitive info in a logger and get the consumers of keystoneauth to use oslo's mask_password where possible) - both options are valid fixes.