https://bz.apache.org/bugzilla/show_bug.cgi?id=60178
--- Comment #7 from Markus <markus.tolksd...@sap.com> --- Would it be so bad to parse the parameters for known sensitive ones? In such cases you could filter those out. Question is - is it easily recognizable that it's a logon request? If so, you might call a specialized routine, which is parsing the parameters and masks them if necessary Best regards, Markus -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org