Uploaded image for project: 'UIMA'
  1. UIMA
  2. UIMA-5212

DUCC Database (db) user "guest" with r/o access should employ private pw

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.2.0-Ducc
    • Component/s: DUCC
    • Labels:
      None

      Description

      Although database user "guest" has just r/o access, the pw should be private since restricted user-supplied data may be visible in the database.

        Activity

        Hide
        lou.degenaro Lou DeGenaro added a comment -

        code is delivered.

        Show
        lou.degenaro Lou DeGenaro added a comment - code is delivered.
        Hide
        lou.degenaro Lou DeGenaro added a comment -

        > add new db_password_guest to ducc.private.properties as part of ducc_post_install
        > employ ducc.private.properties pw for user guest if present, else try to use "guest" as legacy pw for r/o db access

        Show
        lou.degenaro Lou DeGenaro added a comment - > add new db_password_guest to ducc.private.properties as part of ducc_post_install > employ ducc.private.properties pw for user guest if present, else try to use "guest" as legacy pw for r/o db access

          People

          • Assignee:
            lou.degenaro Lou DeGenaro
            Reporter:
            lou.degenaro Lou DeGenaro
          • Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development