From 8e0e86e59cd113fe5872339944e7a93d5ba67fb7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adomas=20Ven=C4=8Dkauskas?= Date: Sun, 20 Dec 2015 13:46:47 +0000 Subject: [PATCH] Closes #882 Hide password in debug output of key request --- chrome/content/zotero/xpcom/http.js | 1 + 1 file changed, 1 insertion(+) diff --git a/chrome/content/zotero/xpcom/http.js b/chrome/content/zotero/xpcom/http.js index dbbc8c056..5280ae57b 100644 --- a/chrome/content/zotero/xpcom/http.js +++ b/chrome/content/zotero/xpcom/http.js @@ -109,6 +109,7 @@ Zotero.HTTP = new function() { if (options.body && typeof options.body == 'string') { var bodyStart = options.body.substr(0, 1024); // Don't display sync password or session id in console + bodyStart = bodyStart.replace(/password":"[^"]+/, 'password":"********'); bodyStart = bodyStart.replace(/password=[^&]+/, 'password=********'); bodyStart = bodyStart.replace(/sessionid=[^&]+/, 'sessionid=********');