zsewasdsdsd opened a new pull request, #4364: URL: https://github.com/apache/logging-log4j2/pull/4364
Fixes #4345. The JMS appender can expose JNDI security credentials through diagnostic strings. This change masks those credentials in both the legacy JMS and Jakarta JMS implementations. This change: * masks `securityCredentials` in `JmsAppender.Builder.toString()`; * masks `Context.SECURITY_CREDENTIALS` in `JmsManagerConfiguration.toString()`; * copies the JNDI properties before masking, so the runtime configuration remains unchanged; * keeps non-sensitive JNDI properties visible in diagnostics; * adds regression coverage for both `log4j-core` and `log4j-jakarta-jms`; * adds a 2.x changelog entry. ## Verification * Before the production fix, the new core regression tests failed because both builder and manager configuration strings contained the clear-text credential. * The equivalent Jakarta JMS regression tests failed for the same reason. * After the fix, both regression test classes pass with 2 tests each and 0 failures/errors. * The existing JMS regression suite plus the new credential tests completed successfully. * Targeted `verify` for `log4j-api-java9`, `log4j-core-java9`, `log4j-core-test`, and `log4j-jakarta-jms` completed successfully. * `git diff --check` passes. * Local Maven runs used `-Dxml.skip=true`. ## Checklist * [x] Base changes on the `2.x` branch. * [x] Non-trivial changes contain an entry file in `src/changelog/.2.x.x`. * [x] Tests are provided. * [x] Relevant module verification succeeds locally. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
