New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable tracker debug output only when specific parameter set #7413
Comments
I think this could lead to abuse, ie an attacker could just spam a machine w/ &debug=1 to cause problems. Maybe it could only be allowed if a INI config setting is set? |
correct, the main reason we can't allow this is the abuse / security risks of logging output to screen. Instead, maybe we could let Super Users configure the Logging in the UI. A bit like this plugin: http://plugins.piwik.org/kDebug but maybe part of core. Maybe also related to viewing the logs in the Admin UI #7239 |
My point was to enable this param only when tracker debug is enabled as well (like this parameter for API calls https://github.com/piwik/piwik/blob/1.12/config/global.ini.php#L491). It would allow printing debug/log info only when param is passed. Also I agree that it should work only when debug is enabled. Point was to make tracker debug possible on high traffic prod instances. Currently we can log only all requests output from tracker to screen/file which virtually makes this debug unusable with 150-200 req/s. Does it make this idea more feasible ? |
You mean something like this?
when |
yes, exactly :) this will allow to display/log output only for particular requests during debug time window and will not affect any requests other than ones we really want to debug. |
PR: #7537 |
I think it would be useful on some ocassions to have ability of selective debug in tracker.
Basically it could be additional parameter, saying "display tracker debug only when &debug present" (preety much alike https://github.com/piwik/piwik/blob/1.12/config/global.ini.php#L491 - not sure when it was removed). Without parameter, tracker wouldn't produce any debug output.
It would allow to debug tracker behaviour without affecting most requests - especially when we want to debug tracker issue on production server with high traffic. Enabling debug for all requests could drastically decrease tracker performance, but couple of manually launched requests with additional param wouldn't cause problems.
The text was updated successfully, but these errors were encountered: