zsewasdsdsd opened a new pull request, #4364:
URL: https://github.com/apache/logging-log4j2/pull/4364

   Fixes #4345.
   
   The JMS appender can expose JNDI security credentials through diagnostic 
strings. This change masks those credentials in both the legacy JMS and Jakarta 
JMS implementations.
   
   This change:
   
   * masks `securityCredentials` in `JmsAppender.Builder.toString()`;
   * masks `Context.SECURITY_CREDENTIALS` in 
`JmsManagerConfiguration.toString()`;
   * copies the JNDI properties before masking, so the runtime configuration 
remains unchanged;
   * keeps non-sensitive JNDI properties visible in diagnostics;
   * adds regression coverage for both `log4j-core` and `log4j-jakarta-jms`;
   * adds a 2.x changelog entry.
   
   ## Verification
   
   * Before the production fix, the new core regression tests failed because 
both builder and manager configuration strings contained the clear-text 
credential.
   * The equivalent Jakarta JMS regression tests failed for the same reason.
   * After the fix, both regression test classes pass with 2 tests each and 0 
failures/errors.
   * The existing JMS regression suite plus the new credential tests completed 
successfully.
   * Targeted `verify` for `log4j-api-java9`, `log4j-core-java9`, 
`log4j-core-test`, and `log4j-jakarta-jms` completed successfully.
   * `git diff --check` passes.
   * Local Maven runs used `-Dxml.skip=true`.
   
   ## Checklist
   
   * [x] Base changes on the `2.x` branch.
   * [x] Non-trivial changes contain an entry file in `src/changelog/.2.x.x`.
   * [x] Tests are provided.
   * [x] Relevant module verification succeeds locally.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to