[jboss-cvs] JBossAS SVN: r60602 - branches/Branch_4_2/security/src/main/org/jboss/security/auth/spi.

jboss-cvs-commits at lists.jboss.org jboss-cvs-commits at lists.jboss.org
Sat Feb 17 19:01:39 EST 2007


Author: scott.stark at jboss.org
Date: 2007-02-17 19:01:38 -0500 (Sat, 17 Feb 2007)
New Revision: 60602

Modified:
   branches/Branch_4_2/security/src/main/org/jboss/security/auth/spi/LdapExtLoginModule.java
Log:
JBAS-4114, mask the BIND_CREDENTIAL in trace logging

Modified: branches/Branch_4_2/security/src/main/org/jboss/security/auth/spi/LdapExtLoginModule.java
===================================================================
--- branches/Branch_4_2/security/src/main/org/jboss/security/auth/spi/LdapExtLoginModule.java	2007-02-17 17:26:03 UTC (rev 60601)
+++ branches/Branch_4_2/security/src/main/org/jboss/security/auth/spi/LdapExtLoginModule.java	2007-02-18 00:01:38 UTC (rev 60602)
@@ -530,11 +530,14 @@
       {
          Properties tmp = new Properties();
          tmp.putAll(env);
-         tmp.setProperty(Context.SECURITY_CREDENTIALS, "***");
+         if( tmp.containsKey(BIND_CREDENTIAL) )
+            tmp.setProperty(BIND_CREDENTIAL, "***");
+         if( tmp.containsKey(Context.SECURITY_CREDENTIALS) )
+            tmp.setProperty(Context.SECURITY_CREDENTIALS, "***");
          log.trace("Logging into LDAP server, env=" + tmp.toString()); 
       }
-   } 
-   
+   }
+
    //JBAS-3438 : Handle "/" correctly
    private String canonicalize(String searchResult)
    {




More information about the jboss-cvs-commits mailing list