bde6abc361d47cc2 PasswordAuthenticator exposes user password in debug log
authorTomas Zeman <tzeman@volny.cz>
Thu, 03 May 2012 13:34:26 +0200
changeset 94 e91d062e38ab
parent 93 8679b6804f4c
child 95 e02d27427caa
bde6abc361d47cc2 PasswordAuthenticator exposes user password in debug log
src/main/scala/fis/aaa/model/Authenticator.scala
--- a/src/main/scala/fis/aaa/model/Authenticator.scala	Thu May 03 11:51:30 2012 +0200
+++ b/src/main/scala/fis/aaa/model/Authenticator.scala	Thu May 03 13:34:26 2012 +0200
@@ -56,9 +56,8 @@
     }}
 }
 
-object PasswordAuthenticator extends Authenticator with UserCrud with Loggable {
+object PasswordAuthenticator extends Authenticator with UserCrud {
   def authenticate(u: User, p: String): Box[User] = byLogin(u.login.get) flatMap { u =>
-    logger.debug("Pass: '%s' '%s' '%s'".format(p, md5(p), u.password.get))
     ((p.length > 0) && (u.password.get == md5(p))).box(u) $ { _ match {
     case Full(_) => // ok
     case _ => S error l10n("error.invalid-password")