[WebSVN] Protect information from command error

View: New views
3 Messages — Rating Filter:   Alert me  

[WebSVN] Protect information from command error

by Yokav - Mailing :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hello,

When there is an error, the command used during the error is displayed.

But if we use a repo with login/password, the command displayed contain
those information !

What's the best solution? Don't display error, display only the error if...

------------------------------------------------------
http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2410628

To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].

Re: [WebSVN] Protect information from command error

by Quinn Taylor :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Yokav -

Just tying up loose ends... Does this occur an the latest version anymore? We've tried to make sure include/svnlook.php only logs sensitive information to the web server log, and doesn't print it in the web page. Please let us know if this still happens for you in trunk.

Thanks,
  - Quinn

On Oct 23, 2009, at 5:24 AM, Yokav wrote:

> Hello,
>
> When there is an error, the command used during the error is displayed.
>
> But if we use a repo with login/password, the command displayed contain
> those information !
>
> What's the best solution? Don't display error, display only the error if...
>
> ------------------------------------------------------
> http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2410628
>
> To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].
------------------------------------------------------
http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2427147

To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].

smime.p7s (4K) Download Attachment

Re: [WebSVN] Protect information from command error

by Yokav - Mailing :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hello,

This error doesn't occur anymore in the last version of the svn. :)
AFAIK because it's not easy to generate an error! ;)

Le 04/12/09 19:28, Quinn Taylor a écrit :

> Yokav -
>
> Just tying up loose ends... Does this occur an the latest version anymore? We've tried to make sure include/svnlook.php only logs sensitive information to the web server log, and doesn't print it in the web page. Please let us know if this still happens for you in trunk.
>
> Thanks,
>    - Quinn
>
> On Oct 23, 2009, at 5:24 AM, Yokav wrote:
>
>> Hello,
>>
>> When there is an error, the command used during the error is displayed.
>>
>> But if we use a repo with login/password, the command displayed contain
>> those information !
>>
>> What's the best solution? Don't display error, display only the error if...
>>
>> ------------------------------------------------------
>> http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2410628
>>
>> To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].
>
> ------------------------------------------------------
> http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2427147
>
> To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].

------------------------------------------------------
http://websvn.tigris.org/ds/viewMessage.do?dsForumId=1547&dsMessageId=2427760

To unsubscribe from this discussion, e-mail: [dev-unsubscribe@...].