Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Revealing debugging information in errors messages #9960

Closed
jaceklubzinski opened this issue Mar 23, 2016 · 1 comment
Closed

Revealing debugging information in errors messages #9960

jaceklubzinski opened this issue Mar 23, 2016 · 1 comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. Enhancement For new feature suggestions that enhance Matomo's capabilities or add a new report, new API etc. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.

Comments

@jaceklubzinski
Copy link

Some of the debugging informations like paths and database name can be available for everyone.
It would be best if on the page appears only information about checking logs.
piwikpath
piwikdbinfo

@tsteur
Copy link
Member

tsteur commented Mar 29, 2016

I think this is behaviour is currently wanted and helpful for most users and we should keep showing these messages. Important is that we don't leak any passwords. In above case we could maybe hide the host and database name.

If someone wants to hide further details we could trigger an event so anybody could modify error message and title if needed. So far it is only possible to modify the rendered error page and this is not really practical to change error messages within a rendered HTML page.

@tsteur tsteur added Enhancement For new feature suggestions that enhance Matomo's capabilities or add a new report, new API etc. c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. labels Mar 29, 2016
@mattab mattab modified the milestone: 2.16.x (LTS) Mar 31, 2016
@mattab mattab added this to the Mid term milestone Jul 14, 2016
@mattab mattab closed this as completed Jun 19, 2017
@mattab mattab added the wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it. label Jun 19, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c: Security For issues that make Matomo more secure. Please report issues through HackerOne and not in Github. Enhancement For new feature suggestions that enhance Matomo's capabilities or add a new report, new API etc. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.
Projects
None yet
Development

No branches or pull requests

3 participants