[cas-dev] logging passwords...

Velpi velpi at industria.be
Fri Jul 28 04:41:11 EDT 2006


Hi

AuthenticationViaFormAction is logging passwords when set to DEBUG. It does that 
because it outputs the request parameters.
It's not really a problem, but it would be best to prevent this somehow in the 
future if possible. In my opinion password mining should not be made easy, even 
for admins...

-- Velpi


More information about the cas-dev mailing list