Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

find a different place for the X-Plex-Token #42

Closed
OttoKerner opened this issue May 3, 2016 · 1 comment
Closed

find a different place for the X-Plex-Token #42

OttoKerner opened this issue May 3, 2016 · 1 comment

Comments

@OttoKerner
Copy link

When supporting users in the Plex Forums, users are often asked to attach their zipped log folders to their error reports.

If they have the HAMA bundle installed, they are publishing their X-Plex-Token, which is a security nightmare and opens up the roads for rogue users accessing the servers.

Ususally, users are asked to clear out their log folders before gathering sets of log files, simply as a precaution to divulge only the necessary amount of information, pertaining to the diagnosis of malfunctions.
Here, it is also unfortunately that the X-Plex-Token is placed into the log folder. If a user is following this request from a supporting forum user, their HAMA install might be incapacitated afterwards.

I therefore ask you to find a different place to store the X-Plex-Token, to avoid the above issues.

@ZeroQI
Copy link
Owner

ZeroQI commented May 5, 2016

It is the scanner that allow as an option users to enter it manually in that file so they have a log per library. It is not generated nor required.

Since both the scanner and agent run on multiple platforms, finding a common working folder path is impossible for the scanner. I could use user folder but then nobody will find the logs and could crash on some platforms... (would have used the agent ressource folder if the agent is responsible, which it is not)

Closing since i got no reply and it is a scanner issue and report imply i generate the token which isn't true, the file is empty and manually filled, and agent+scanner work fine without it entered

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants