Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Privacy Settings: Do not send token_auth via GET and POST #8497

Closed
tsteur opened this issue Aug 6, 2015 · 2 comments
Closed

Privacy Settings: Do not send token_auth via GET and POST #8497

tsteur opened this issue Aug 6, 2015 · 2 comments
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. duplicate For issues that already existed in our issue tracker and were reported previously. Major Indicates the severity or impact or benefit of an issue is much higher than normal but not critical.

Comments

@tsteur
Copy link
Member

tsteur commented Aug 6, 2015

See eg #8002 (diff) , #8002 (diff) , #8002 (diff) , ...

It shouldn't be sent as GET as the token could appear in server logs

@tsteur tsteur added the c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. label Aug 6, 2015
@Joey3000
Copy link
Contributor

See also #7349 :)

@mattab mattab added this to the Short term milestone Sep 18, 2015
@mattab mattab added the Major Indicates the severity or impact or benefit of an issue is much higher than normal but not critical. label Sep 18, 2015
@Findus23
Copy link
Member

Findus23 commented Aug 4, 2020

closing in favour of #7349

@Findus23 Findus23 closed this as completed Aug 4, 2020
@Findus23 Findus23 added the duplicate For issues that already existed in our issue tracker and were reported previously. label Aug 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. duplicate For issues that already existed in our issue tracker and were reported previously. Major Indicates the severity or impact or benefit of an issue is much higher than normal but not critical.
Projects
None yet
Development

No branches or pull requests

4 participants