I believe this bug report says that that replication token contains the
secrets. So it does, if the server replies with server error response.
Pastebinning this response would disclose personal tokens. So I believe
either such messages need to be placed to some kind of private log and
only case_clause should be returned or these messages should be parsed
for _secret  items or they should not be printed to the log at all
leading to lowered amount of developer-friendly info but keeping user
data safe.

-- 
Replication log contains token and token secret so can't be pastebinned
https://bugs.launchpad.net/bugs/460974
You received this bug notification because you are a member of Ubuntu
Bugs, which is a direct subscriber.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to