Skip to content

The api key in the st2api log is not obfuscated #4589

@jinpingh

Description

@jinpingh
SUMMARY

The user found in clean API key in query request (for the load balancer health check)
GET /api/v1/?st2-api-key=foo HTTP/1.1

ISSUE TYPE
  • Bug Report
STACKSTORM VERSION

st2 2.10.3, on Python 2.7.12

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions