You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@trafficcontrol.apache.org by GitBox <gi...@apache.org> on 2022/07/11 19:16:55 UTC

[GitHub] [trafficcontrol] jhg03a opened a new issue, #6953: Make sensitive fields require extra click to show contents in TP

jhg03a opened a new issue, #6953:
URL: https://github.com/apache/trafficcontrol/issues/6953

   <!--
   ************ STOP!! ************
   If this issue identifies a security vulnerability, DO NOT submit it! Instead, contact
   the Apache Traffic Control Security Team at security@trafficcontrol.apache.org and follow the
   guidelines at https://apache.org/security regarding vulnerability disclosure.
   
   - For *SUPPORT QUESTIONS*, use the #traffic-control channel on the ASF slack (https://s.apache.org/tc-slack-request)
   or the Traffic Control Users mailing list (send an email to users-subscribe@trafficcontrol.apache.org to subscribe).
   - Before submitting, please **SEARCH GITHUB** for a similar issue or PR
       * https://github.com/apache/trafficcontrol/issues
       * https://github.com/apache/trafficcontrol/pulls
   -->
   
   <!-- Do not submit security vulnerabilities or support requests here - see above -->
   ## This Improvement request (usability, performance, tech debt, etc.) affects these Traffic Control components:
   <!-- delete all those that don't apply -->
   - Traffic Portal
   
   ## Current behavior:
   <!-- Describe how the current features are insufficient. -->
   Currently showing a delivery service or SSL data of a delivery service displays sensitive data automatically.  If you're doing something like demonstrating TP, this can inadvertently disclose that information to parties not entitled to see it.  
   
   
   ## New behavior:
   <!-- Describe how this change would improve Traffic Control -->
   It would be nice to have something like a show button that displays that content on pages with other insensitive data.  Specifically this would apply to private SSL Key data, out-of-band interface credentials, and free-form ATS fields on delivery services such as raw remap.  While parameters could also contain sensitive information, I did not include them because they are individually scoped and do not inherently share visual space with non-sensitive data.  Should any of this data be included in grids, they also should be obscured.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@trafficcontrol.apache.org.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [trafficcontrol] rawlinp commented on issue #6953: Make sensitive fields require extra click to show contents in TP

Posted by GitBox <gi...@apache.org>.
rawlinp commented on issue #6953:
URL: https://github.com/apache/trafficcontrol/issues/6953#issuecomment-1180808190

   Related: https://github.com/apache/trafficcontrol/issues/3258


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@trafficcontrol.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org