Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-20874

Mask passwords in Request resource responses

    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 2.2.2
    • 3.0.0, 2.5.1, 2.4.3
    • ambari-server
    • None

    Description

      Mask the data for sensitive fields and properties in Request resource responses to protect that data.

      org.apache.ambari.server.utils.SecretReference#maskPasswordInPropertyMap is used org.apache.ambari.server.controller.internal.StageResourceProvider to protected sensitive data. The same technique should be used in org.apache.ambari.server.controller.internal.RequestResourceProvider.

      Attachments

        1. AMBARI-20874_branch-2.4_01.patch
          6 kB
          Robert Levas
        2. AMBARI-20874_branch-2.5_01.patch
          6 kB
          Robert Levas
        3. AMBARI-20874_trunk_01.patch
          6 kB
          Robert Levas

        Issue Links

          Activity

            People

              rlevas Robert Levas
              rlevas Robert Levas
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: