Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
Bug: API keys written to the error log in cleartext when using ?key= auth
-
When an API request using the ?key= query-string form throws, the Diagnostic Center records the full request URL including the key (e.g. Unhandled exception processing http://host:8622/api/json/?key=...). The key is then readable by anyone with Diagnostic Center access or via LogMessages_GetMessages. Suggest redacting key when logging request URLs. (Workaround on our side: send the key as the X-ApiKey header instead.)
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login