diff options
author | Grant Murphy <gmurphy@redhat.com> | 2014-06-23 05:07:54 +0000 |
---|---|---|
committer | Grant Murphy <gmurphy@redhat.com> | 2014-06-23 05:07:54 +0000 |
commit | 264f3b0d9640edeac743f339786e0a3b22c0f6c2 (patch) | |
tree | 8fa931c00db649d2868d14b54e141e8ffcfbc4e3 | |
parent | a2c909ca4bb32d4a82e2658a6e1faa972f9fea12 (diff) | |
download | ceilometer-264f3b0d9640edeac743f339786e0a3b22c0f6c2.tar.gz |
remove token from notifier middleware
oslo-incubator sync to address the security bug
in middleware (as below).
notifier middleware is capturing token and sending it to MQ. this
is not advisable so we should filter it out.
Change-Id: Ia1bfa1bd24989681db1d2f385defc12e69a01f8d
Closes-Bug: #1321080
-rw-r--r-- | ceilometer/openstack/common/middleware/audit.py | 2 | ||||
-rw-r--r-- | ceilometer/openstack/common/middleware/notifier.py | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/ceilometer/openstack/common/middleware/audit.py b/ceilometer/openstack/common/middleware/audit.py index 1bda8d11..bb69e313 100644 --- a/ceilometer/openstack/common/middleware/audit.py +++ b/ceilometer/openstack/common/middleware/audit.py @@ -1,6 +1,6 @@ # vim: tabstop=4 shiftwidth=4 softtabstop=4 -# Copyright (c) 2013 OpenStack LLC. +# Copyright (c) 2013 OpenStack Foundation # All Rights Reserved. # # Licensed under the Apache License, Version 2.0 (the "License"); you may diff --git a/ceilometer/openstack/common/middleware/notifier.py b/ceilometer/openstack/common/middleware/notifier.py index ab744ff0..8006fe74 100644 --- a/ceilometer/openstack/common/middleware/notifier.py +++ b/ceilometer/openstack/common/middleware/notifier.py @@ -66,7 +66,7 @@ class RequestNotifier(base.Middleware): """ return dict((k, v) for k, v in environ.iteritems() - if k.isupper()) + if k.isupper() and k != 'HTTP_X_AUTH_TOKEN') @log_and_ignore_error def process_request(self, request): |