Menu

#40 error log includes personal information

0.5.7
open
nobody
5
2007-11-05
2007-11-05
No

When using kcheckgmail compiled with full debug information, it writes sensitive personal information to logs, in lines such as:

kcheckgmail: [void GMail::checkLoginParams()] Using [removed] as username and as domain

or

kcheckgmail: [void GMailWalletManager::slotWalletChangedStatus()] Got pass: [removed]

Since the project homepage instructs users to post these error logs on the bug tracker, which is a public page, kcheckgmail should at least obscure the login and password from the logs.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB