[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-04-04 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17833859#comment-17833859 ] Jacques Le Roux commented on OFBIZ-10507: - Thanks Michael, should we not close? >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-04-04 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17833844#comment-17833844 ] Michael Brohl commented on OFBIZ-10507: --- Thanks for the heads up Jacques, I've merged the PR. >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-04-04 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17833843#comment-17833843 ] ASF subversion and git services commented on OFBIZ-10507: - Commit

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-04-04 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17833834#comment-17833834 ] Jacques Le Roux commented on OFBIZ-10507: - Hi Michael, Do you want that I push the PR or is

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-03-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17831185#comment-17831185 ] Jacques Le Roux commented on OFBIZ-10507: - Hi, I did not look at all possible messages in

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-03-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17830456#comment-17830456 ] Jacques Le Roux commented on OFBIZ-10507: - Hi Michael, I think I was not clear. I did not

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-03-25 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17830435#comment-17830435 ] Michael Brohl commented on OFBIZ-10507: --- I was waiting for feedback to the provided PR. I will

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2024-03-22 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17829943#comment-17829943 ] Jacques Le Roux commented on OFBIZ-10507: - Hi, I'm reviewing pending PRs, what's up here? >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2021-02-01 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17276496#comment-17276496 ] Michael Brohl commented on OFBIZ-10507: --- [~bjugl] can you provide a PR based on your patch? >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-10 Thread Michael Brohl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16576101#comment-16576101 ] Michael Brohl commented on OFBIZ-10507: --- [~deepak.dixit], the problem I see with with the current

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572902#comment-16572902 ] Deepak Dixit commented on OFBIZ-10507: -- It helps to identify the root cause of login failure, and

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572869#comment-16572869 ] Benjamin Jugl commented on OFBIZ-10507: --- Let me rephrase: What relevant information is there, to

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572861#comment-16572861 ] Deepak Dixit commented on OFBIZ-10507: -- Also we can have two type of generic message, In this case

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572846#comment-16572846 ] Deepak Dixit commented on OFBIZ-10507: -- [~bjugl] error logging helps developer while debugging, it

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572836#comment-16572836 ] Benjamin Jugl commented on OFBIZ-10507: --- I partly agree. Generic messanges for the user are a good

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572708#comment-16572708 ] Deepak Dixit commented on OFBIZ-10507: -- The login page is prone to a user-enumeration attack, Error