i2b2 Sponsored Project/s:
Testing Notes:
Hide
Tested with Mike Mendis and the password no longer displays. The tags for the password are sent in the xml but the actually password is replaced with asterisks.
This issue is now working correctly and can be included in the 1.7.05 release.
Show
Tested with Mike Mendis and the password no longer displays. The tags for the password are sent in the xml but the actually password is replaced with asterisks.
This issue is now working correctly and can be included in the 1.7.05 release.
In the JBoss server log for the edu.harvard.i2b2.pm.ws.PMService::Received Request PDO Element, the user password is displaying in the <security> section.
Although this information is only displayed when the DEBUG level is turned on it can be problematic for those sites that do not have their passwords encrypted. Encrypted passwords will display an encrypted Session Key instead of the password. This session key does time out and can not be used when logging into either the i2b2 Web Client or the Workbench. It can however be used to access the server if the user viewing the logs has a method of querying the server directly.
Bottom line is user passwords should not display in the JBoss logs regardless of whether or not DEBUG is turned on.
{"report":{"fcp":586.0999994277954,"ttfb":163.5,"pageVisibility":"visible","entityId":10374,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"29a03d0a-decf-4e68-99b4-1ef4a72f6bae","navigationType":0,"readyForUser":640.6999998092651,"redirectCount":0,"resourceLoadedEnd":685.3999996185303,"resourceLoadedStart":168.39999961853027,"resourceTiming":[{"duration":7.100000381469727,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/7fd763ecdf5ed1f47fc4d22fa8382e97-CDN/4x9nqn/820011/16zrvj4/49fa3aa3d35a2cc689cbf274e66cc41a/_/download/contextbatch/css/_super/batch.css","startTime":168.39999961853027,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":168.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":175.5,"responseStart":0,"secureConnectionStart":0},{"duration":7.199999809265137,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/898b8076c5e82f53cd816ca393e45a56-CDN/4x9nqn/820011/16zrvj4/f614b50eeb842ebd1ea7ab2903699907/_/download/contextbatch/css/project.issue.navigator,jira.view.issue,jira.global,atl.general,-_super/batch.css?jira.create.linked.issue=true&richediton=true","startTime":168.5999994277954,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":168.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":175.79999923706055,"responseStart":0,"secureConnectionStart":0},{"duration":129.70000076293945,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/4c9c503fe98f210445831b0d7b0cdc33-CDN/4x9nqn/820011/16zrvj4/49fa3aa3d35a2cc689cbf274e66cc41a/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":168.79999923706055,"connectEnd":202.89999961853027,"connectStart":179.5,"domainLookupEnd":179.5,"domainLookupStart":179.5,"fetchStart":168.79999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":203.19999980926514,"responseEnd":298.5,"responseStart":220.39999961853027,"secureConnectionStart":190.89999961853027},{"duration":201.69999980926514,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/694e598c1ae48b0f96655173631cd247-CDN/4x9nqn/820011/16zrvj4/f614b50eeb842ebd1ea7ab2903699907/_/download/contextbatch/js/project.issue.navigator,jira.view.issue,jira.global,atl.general,-_super/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":169,"connectEnd":203.5999994277954,"connectStart":180.0999994277954,"domainLookupEnd":180.0999994277954,"domainLookupStart":180.0999994277954,"fetchStart":169,"redirectEnd":0,"redirectStart":0,"requestStart":203.5999994277954,"responseEnd":370.69999980926514,"responseStart":228.29999923706055,"secureConnectionStart":191.5999994277954},{"duration":57.70000076293945,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/53f54e0ac3f00bb56b136b4d2fff2853-CDN/4x9nqn/820011/16zrvj4/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":169.29999923706055,"connectEnd":204.39999961853027,"connectStart":180,"domainLookupEnd":180,"domainLookupStart":180,"fetchStart":169.29999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":204.39999961853027,"responseEnd":227,"responseStart":226.19999980926514,"secureConnectionStart":191.19999980926514},{"duration":99.30000019073486,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":169.39999961853027,"connectEnd":252.5,"connectStart":226.89999961853027,"domainLookupEnd":226.89999961853027,"domainLookupStart":226.89999961853027,"fetchStart":169.39999961853027,"redirectEnd":0,"redirectStart":0,"requestStart":252.69999980926514,"responseEnd":268.69999980926514,"responseStart":267.29999923706055,"secureConnectionStart":239.5},{"duration":140.30000019073486,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":169.69999980926514,"connectEnd":294.0999994277954,"connectStart":268.5,"domainLookupEnd":268.5,"domainLookupStart":268.5,"fetchStart":169.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":294.19999980926514,"responseEnd":310,"responseStart":308.5999994277954,"secureConnectionStart":281.0999994277954},{"duration":10.90000057220459,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/30748292e4ca68be6947d7969829384b-CDN/4x9nqn/820011/16zrvj4/4f66da484ef7d95a2a604d3ab014374c/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":169.79999923706055,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":169.79999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":180.69999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":166.5,"initiatorType":"script","name":"https://community.i2b2.org/jira/rest/api/1.0/shortcuts/820011/a9e270f026ecabffc9a59343e5439391/shortcuts.js?context=issuenavigation&context=issueaction","startTime":170,"connectEnd":322,"connectStart":298.3999996185303,"domainLookupEnd":298.3999996185303,"domainLookupStart":298.3999996185303,"fetchStart":170,"redirectEnd":0,"redirectStart":0,"requestStart":322,"responseEnd":336.5,"responseStart":335.5999994277954,"secureConnectionStart":310.29999923706055},{"duration":13.699999809265137,"initiatorType":"link","name":"https://community.i2b2.org/jira/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/4x9nqn/820011/16zrvj4/efa42a25652b26dfd802540c024826b3/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":211.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":211.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":225.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":313.19999980926514,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/8087506fefd02b4096991c90836b49f6-CDN/4x9nqn/820011/16zrvj4/efa42a25652b26dfd802540c024826b3/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":211.5999994277954,"connectEnd":504.79999923706055,"connectStart":481.19999980926514,"domainLookupEnd":481.19999980926514,"domainLookupStart":481.19999980926514,"fetchStart":211.5999994277954,"redirectEnd":0,"redirectStart":0,"requestStart":505,"responseEnd":524.7999992370605,"responseStart":521.6999998092651,"secureConnectionStart":492.5999994277954},{"duration":331.8999996185303,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":233.69999980926514,"connectEnd":549.5,"connectStart":523.0999994277954,"domainLookupEnd":523.0999994277954,"domainLookupStart":523.0999994277954,"fetchStart":233.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":549.5,"responseEnd":565.5999994277954,"responseStart":563.8999996185303,"secureConnectionStart":536.1999998092651},{"duration":79.39999961853027,"initiatorType":"xmlhttprequest","name":"https://community.i2b2.org/jira/rest/webResources/1.0/resources","startTime":487.19999980926514,"connectEnd":547.3999996185303,"connectStart":524.2999992370605,"domainLookupEnd":524.2999992370605,"domainLookupStart":524.2999992370605,"fetchStart":487.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":547.3999996185303,"responseEnd":566.5999994277954,"responseStart":564.6999998092651,"secureConnectionStart":535.5},{"duration":104.20000076293945,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":502.29999923706055,"connectEnd":591.5,"connectStart":565.3999996185303,"domainLookupEnd":565.3999996185303,"domainLookupStart":565.3999996185303,"fetchStart":502.29999923706055,"redirectEnd":0,"redirectStart":0,"requestStart":591.5,"responseEnd":606.5,"responseStart":605.5999994277954,"secureConnectionStart":578.1999998092651},{"duration":99.10000038146973,"initiatorType":"script","name":"https://community.i2b2.org/jira/s/d41d8cd98f00b204e9800998ecf8427e-CDN/4x9nqn/820011/16zrvj4/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-atl.general/batch.js","startTime":586.2999992370605,"connectEnd":668.3999996185303,"connectStart":642.2999992370605,"domainLookupEnd":642.2999992370605,"domainLookupStart":642.2999992370605,"fetchStart":586.2999992370605,"redirectEnd":0,"redirectStart":0,"requestStart":668.5,"responseEnd":685.3999996185303,"responseStart":684.1999998092651,"secureConnectionStart":655.0999994277954},{"duration":53.5,"initiatorType":"iframe","name":"https://community.i2b2.org/jira/plugins/servlet/gadgets/ifr?container=atlassian&mid=0&country=US&lang=en&view=issuetab&view-params=%7B%22writable%22%3A%22false%22%7D&st=atlassian%3Ad2iS2NQtrR58QCeCOLJqNgpon9ssN3tzs0NNCic8Qv0hgwlS15rmGcQr04qeelyhmuzTcu8sWoahV14lcCEicAvYfesyqSeMLKdZrrwVJd%2BUNmsstklDj3YKjT8F%2FoDyx8MOWJ3Z44Ckm1%2FCMkRYVaNprEN7WVVfQPcefyvbSfW%2FA5Fs54uA2cox3GLYjPc%2FBhrnCHAbZtJFTVx%2FP5F52X5pkxFMjB1pp9q4XdaoIJ75fq2J2UhGqpgu8aWHlxm7%2FVKe%2FBpcW0SND7DBtrELVeLO698%3D&up_isConfigured=true&up_isReallyConfigured=true&up_title=Activity+Stream&up_titleRequired=false&up_numofentries=20&up_refresh=false&up_maxProviderLabelCharacters=50&up_rules=%7B%22providers%22%3A%5B%7B%22provider%22%3A%22streams%22%2C%22rules%22%3A%5B%7B%22provider%22%3A%22streams%22%2C%22rule%22%3A%22issue-key%22%2C%22type%22%3A%22string%22%2C%22value%22%3A%22CORE-158%22%2C%22operator%22%3A%22is%22%7D%2C%7B%22provider%22%3A%22streams%22%2C%22rule%22%3A%22key%22%2C%22type%22%3A%22select%22%2C%22value%22%3A%5B%22CORE%22%5D%2C%22operator%22%3A%22is%22%7D%5D%7D%5D%7D&up_renderingContext=view-issue&up_keys=&up_itemKeys=&up_username=&url=https%3A%2F%2Fcommunity.i2b2.org%2Fjira%2Frest%2Fgadgets%2F1.0%2Fg%2Fcom.atlassian.streams.streams-jira-plugin%2Fgadgets%2Factivitystream-gadget.xml&libs=auth-refresh#rpctoken=158906378","startTime":677.8999996185303,"connectEnd":712.7999992370605,"connectStart":708.8999996185303,"domainLookupEnd":708.8999996185303,"domainLookupStart":708.8999996185303,"fetchStart":677.8999996185303,"redirectEnd":0,"redirectStart":0,"requestStart":712.7999992370605,"responseEnd":731.3999996185303,"responseStart":730.6999998092651,"secureConnectionStart":708.8999996185303}],"fetchStart":0,"domainLookupStart":33,"domainLookupEnd":82,"connectStart":82,"connectEnd":120,"secureConnectionStart":94,"requestStart":120,"responseStart":164,"responseEnd":408,"domLoading":167,"domInteractive":692,"domContentLoadedEventStart":692,"domContentLoadedEventEnd":726,"domComplete":901,"loadEventStart":901,"loadEventEnd":903,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":672.7999992370605},{"name":"bigPipe.sidebar-id.end","time":673.5},{"name":"bigPipe.activity-panel-pipe-id.start","time":673.6999998092651},{"name":"bigPipe.activity-panel-pipe-id.end","time":678},{"name":"activityTabFullyLoaded","time":738.2999992370605}],"measures":[],"correlationId":"3cc666bb29f7cf","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":275,"dbReadsTimeInMs":10,"dbConnsTimeInMs":21,"applicationHash":"0629dd8d260e3954ece49053e565d01dabe11609","experiments":[]}}