Uploaded image for project: 'cTAKES'
  1. cTAKES
  2. CTAKES-455

Password shown in clear in logs

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • 4.0.1
    • None
    • None

    Description

      When authentication to UMLS fails, the error shows the passwords used.

      $ ./bin/runctakesCVD.sh -desc desc/ctakes-clinical-pipeline/desc/analysis_engine/AggregatePlaintextFastUMLSProcessor.xml
      (...)
      03 Sep 2017 10:35:49 ERROR UmlsUserApprover -   UMLS Account at https://uts-ws.nlm.nih.gov/restful/isValidUMLSUser is not valid for user ###### with ######
      

      Not to log passwords is a security policy enforced in almost all production systems (more here)

      Attachments

        Activity

          People

            seanfinan Sean Finan
            alexz Alex Zbarcea
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: