Project

General

Profile

Actions

Cleanup #49216

closed

mgr/dashboard: delete EOF when reading passwords from file

Added by Alfonso Martínez about 3 years ago. Updated about 3 years ago.

Status:
Resolved
Priority:
High
Category:
General - Back-end
Target version:
% Done:

0%

Tags:
Backport:
pacific octopus nautilus
Reviewed:
Affected Versions:
Pull request ID:

Description

When executing:
1) echo "myPassw0rd" > /tmp/my_secret.txt
(Notice: not using "-n" option; also reproducible by editing the file with text editor that adds a newline separator when saving.)

2) ceph dashboard ac-user-set-password admin -i /tmp/my_secret.txt
(The command succeeds.)

RESULT: the user is not able to log in through dashboard.

EXPECTED RESULT: be able to log in.

FIX: Sanitize the input.


Related issues 4 (0 open4 closed)

Related to Dashboard - Subtask #48355: mgr/dashboard: CLI commands: read passwords from fileResolvedAlfonso Martínez

Actions
Copied to Dashboard - Backport #49270: pacific: mgr/dashboard: delete EOF when reading passwords from fileResolvedAlfonso MartínezActions
Copied to Dashboard - Backport #49271: nautilus: mgr/dashboard: delete EOF when reading passwords from fileResolvedAlfonso MartínezActions
Copied to Dashboard - Backport #49272: octopus: mgr/dashboard: delete EOF when reading passwords from fileResolvedAlfonso MartínezActions
Actions #1

Updated by Alfonso Martínez about 3 years ago

  • Status changed from In Progress to Fix Under Review
  • Assignee set to Alfonso Martínez
  • Pull request ID set to 39362
Actions #2

Updated by Alfonso Martínez about 3 years ago

  • Related to Subtask #48355: mgr/dashboard: CLI commands: read passwords from file added
Actions #3

Updated by Ernesto Puerta about 3 years ago

  • Status changed from Fix Under Review to Pending Backport
Actions #4

Updated by Ernesto Puerta about 3 years ago

  • Priority changed from Normal to High
Actions #5

Updated by Backport Bot about 3 years ago

  • Copied to Backport #49270: pacific: mgr/dashboard: delete EOF when reading passwords from file added
Actions #6

Updated by Backport Bot about 3 years ago

  • Copied to Backport #49271: nautilus: mgr/dashboard: delete EOF when reading passwords from file added
Actions #7

Updated by Backport Bot about 3 years ago

  • Copied to Backport #49272: octopus: mgr/dashboard: delete EOF when reading passwords from file added
Actions #8

Updated by Loïc Dachary about 3 years ago

  • Status changed from Pending Backport to Resolved

While running with --resolve-parent, the script "backport-create-issue" noticed that all backports of this issue are in status "Resolved" or "Rejected".

Actions #9

Updated by Ernesto Puerta about 3 years ago

  • Project changed from mgr to Dashboard
  • Category changed from 146 to General - Back-end
Actions

Also available in: Atom PDF