You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@druid.apache.org by GitBox <gi...@apache.org> on 2020/06/29 19:46:51 UTC

[GitHub] [druid] suneet-s opened a new pull request #10097: Do not echo back username on auth failure

suneet-s opened a new pull request #10097:
URL: https://github.com/apache/druid/pull/10097


   ### Description
   
   Clean up the error message that is sent to the user on authentication failures by not including the username.
   
   <hr>
   
   This PR has:
   - [x] been self-reviewed.
   - [x] added unit tests or modified existing tests to cover new code paths, ensuring the threshold for [code coverage](https://github.com/apache/druid/blob/master/dev/code-review/code-coverage.md) is met.
   - [ ] added integration tests.
   - [x] been tested in a test Druid cluster.


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-656828081


   This pull request **fixes 1 alert** when merging b7305a43218948c16e814461d9793bc7b5aace79 into 54a8fb827df6ca2d7b0f1e86656d0cd5a978f273 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-3f8f06aa2ab5c44b14f7a6b09d35b0c69471cb87)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-651982169


   This pull request **fixes 1 alert** when merging 567402357dc8ecff9053a756db69cf063a9d523e into fc555980e8cadc61fcb8cee9d6dadec9cf0e0496 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-640b72e52fd485f730bce1c89f807a0e6f25ae8e)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-652689662


   This pull request **fixes 1 alert** when merging 37e88dab5afdc8ff077f6503a88db79faa5f7a89 into 477335abb4fe3e872a1b8f71d9c2bd90e4315fbc - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-b711591b3e76bbe446fa20ef95d9291e56b236c8)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-652601110


   This pull request **fixes 1 alert** when merging a08f140cd9c07f7116173bf987d4a535b3bc95ae into d3497a6581c69f810090f5180f1f18328b06c781 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-344f5b6eb881f4ffba1ad3995c1c7a9f3a9972f5)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-652047647


   This pull request **fixes 1 alert** when merging e330690801671a0e966b44a5732335b1e0d9e95d into c01fd561825286a9b8888c3b3c14d3d63eb93af5 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-b21c7cd770d35a732de44c8928da282ec613ab9e)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-651360597


   This pull request **fixes 1 alert** when merging 3ab0b5623420ff417f84989e4105442eac2b209f into 35c7c0ec25405bed6f9a379a135d9cf42bea5d16 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-d7a38ccb2c214af0cbbbd5ea1c81fb33bec1ab93)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] lgtm-com[bot] commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
lgtm-com[bot] commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-652489374


   This pull request **fixes 1 alert** when merging 01999dae21e5d60fa5cf9344e6d0a0a30c95ace6 into d3497a6581c69f810090f5180f1f18328b06c781 - [view on LGTM.com](https://lgtm.com/projects/g/apache/druid/rev/pr-266ed1ec3397ce70a967cf34539dddd7f40d02dd)
   
   **fixed alerts:**
   
   * 1 for Cross\-site scripting


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] suneet-s commented on pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
suneet-s commented on pull request #10097:
URL: https://github.com/apache/druid/pull/10097#issuecomment-652667680


   Since this wasn't an issue before this patch, I've removed the label `Security` @clintropolis please add it back / lmk if it's needed. 


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org


[GitHub] [druid] suneet-s merged pull request #10097: Do not echo back username on auth failure

Posted by GitBox <gi...@apache.org>.
suneet-s merged pull request #10097:
URL: https://github.com/apache/druid/pull/10097


   


----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

For queries about this service, please contact Infrastructure at:
users@infra.apache.org



---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscribe@druid.apache.org
For additional commands, e-mail: commits-help@druid.apache.org