Project

General

Profile

Bug #9784

status.php: Sanitize bandwidthd db password

Added by Viktor Gurov 4 months ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Web Interface
Target version:
Start date:
09/23/2019
Due date:
% Done:

100%

Estimated time:
Affected Version:
2.5.0
Affected Architecture:

Description

config-satinized.xml keeps <postgresqlpasswordenc>:

<bandwidthd>
                        <config>
                                <enable>on</enable>
                                <active_interface>lan</active_interface>
                                <interface_array>lan</interface_array>
                                <subnets_extra></subnets_extra>
                                <promiscuous></promiscuous>
                                <sensorid></sensorid>
                                <drawgraphs>on</drawgraphs>
                                <meta_refresh></meta_refresh>
                                <skipintervals></skipintervals>
                                <graphcutoff></graphcutoff>
                                <outputcdf></outputcdf>
                                <recovercdf></recovercdf>
                                <graph_log_info></graph_log_info>
                                <outputpostgresql>on</outputpostgresql>
                                <postgresqlhost>10.1.1.1</postgresqlhost>
                                <postgresqldatabase>bwdb1</postgresqldatabase>
                                <postgresqlusername>bwdbuser</postgresqlusername>
                                <postgresqlpasswordenc>YndkYnBhc3M=</postgresqlpasswordenc>
                                <advfilter></advfilter>
                        </config>
                </bandwidthd>

Associated revisions

Revision 1f2be937 (diff)
Added by Jim Pingle 4 months ago

Redact BandwidthD postgres db password. Fixes #9784

(cherry picked from commit ca3129138b9866f5c82ff80d59eeed3f746367a1)

Revision 016b6625 (diff)
Added by Jim Pingle 4 months ago

Redact BandwidthD postgres db password. Fixes #9784

History

#1 Updated by Jim Pingle 4 months ago

  • Assignee set to Jim Pingle
  • Target version set to 2.5.0

#2 Updated by Jim Pingle 4 months ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

#3 Updated by Viktor Gurov 4 months ago

Jim Pingle wrote:

Applied in changeset 1f2be937ddbaf04a1704cac2aea3fc66bb196013.

<postgresqlpasswordenc>xxxxx</postgresqlpasswordenc>

Sanitized ok
Resolved

#4 Updated by Jim Pingle 4 months ago

  • Status changed from Feedback to Resolved

#5 Updated by Jim Pingle 2 months ago

  • Private changed from Yes to No

#6 Updated by Jim Pingle about 2 months ago

  • Target version changed from 2.5.0 to 2.4.5

#7 Updated by Jim Pingle about 2 months ago

  • Status changed from Resolved to Feedback

Needs checked and/or tested again on 2.4.5 snapshots

#8 Updated by Viktor Gurov about 1 month ago

Jim Pingle wrote:

Needs checked and/or tested again on 2.4.5 snapshots

tested on 2.4.5.a.20191209.0732

Resolved

#9 Updated by Jim Pingle about 1 month ago

  • Status changed from Feedback to Resolved

Also available in: Atom PDF