[jboss-cvs] JBossAS SVN: r112731 - projects/security/security-jboss-sx/branches/Branch_2_0/jbosssx/src/main/java/org/jboss/security/authorization/resources.

jboss-cvs-commits at lists.jboss.org jboss-cvs-commits at lists.jboss.org
Wed Mar 7 06:40:09 EST 2012


Author: tfonteyn
Date: 2012-03-07 06:40:07 -0500 (Wed, 07 Mar 2012)
New Revision: 112731

Modified:
   projects/security/security-jboss-sx/branches/Branch_2_0/jbosssx/src/main/java/org/jboss/security/authorization/resources/WebResource.java
Log:
[JBPAPP-8089] filtering j_password and printing parameter names

Modified: projects/security/security-jboss-sx/branches/Branch_2_0/jbosssx/src/main/java/org/jboss/security/authorization/resources/WebResource.java
===================================================================
--- projects/security/security-jboss-sx/branches/Branch_2_0/jbosssx/src/main/java/org/jboss/security/authorization/resources/WebResource.java	2012-03-06 15:27:07 UTC (rev 112730)
+++ projects/security/security-jboss-sx/branches/Branch_2_0/jbosssx/src/main/java/org/jboss/security/authorization/resources/WebResource.java	2012-03-07 11:40:07 UTC (rev 112731)
@@ -191,10 +191,18 @@
          for(;enparam.hasMoreElements();)
          {
             String paramName = (String)enparam.nextElement();
-            String[] paramValues = httpRequest.getParameterValues(paramName);
-            int len = paramValues != null ? paramValues.length : 0;
-            for(int i = 0 ; i < len ; i++)
-               sb.append(paramValues[i]).append("::"); 
+            sb.append(paramName).append("=");
+            if (paramName.equalsIgnoreCase("j_password")) 
+            {
+               sb.append("***");
+            }
+            else
+            {
+               String[] paramValues = httpRequest.getParameterValues(paramName);
+               int len = paramValues != null ? paramValues.length : 0;
+               for(int i = 0 ; i < len ; i++)
+                  sb.append(paramValues[i]).append("::"); 
+            }
             sb.append(",");
          } 
       } 
@@ -213,4 +221,4 @@
       sb.append("]");
       return sb.toString();
    } 
-}
\ No newline at end of file
+}



More information about the jboss-cvs-commits mailing list