Permalink
Browse files

Remove the password from the debugging output of the pc-usermanager -…

… it was being saved to ~/xsession-errors and is a security vulnerability.

The password is just commneted out now with a note - be sure to re-comment it before committing changes to the usermanager if you needed it for debugging your development version.
  • Loading branch information...
1 parent 490345a commit c823860fffa32ba8dfe753a70b29e6617b765258 Ken Moore committed Oct 3, 2013
Showing with 3 additions and 1 deletion.
  1. +3 −1 src-qt4/pc-usermanager/simpleaddcode.cpp
@@ -181,7 +181,9 @@ void SimpleAddCode::submit()
switch (passError)
{
case 0:
- qDebug() << "Case 0 was found!!!........." + username + " pass: " + password;
+ qDebug() << "Case 0 was found!!!........." + username; //+ " pass: " + password;
+ //Do NOT show the password on comitted versions - this can get saved to a log file on the system (~/.xsession-errors)
+
//back->changePassword(username, password);
close();
break;

0 comments on commit c823860

Please sign in to comment.