Skip to content

Commit 46a908d

Browse files
committed
fixed CWE-532 in FacebookAuthFilter - improper logging of sensitive information
1 parent d0ef6f9 commit 46a908d

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

para-server/src/main/java/com/erudika/para/server/security/filters/FacebookAuthFilter.java

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,11 +28,11 @@
2828
import com.erudika.para.server.security.UserAuthentication;
2929
import com.fasterxml.jackson.core.JsonProcessingException;
3030
import com.fasterxml.jackson.databind.ObjectReader;
31+
import jakarta.servlet.http.HttpServletRequest;
32+
import jakarta.servlet.http.HttpServletResponse;
3133
import java.io.IOException;
3234
import java.util.Map;
3335
import java.util.concurrent.TimeUnit;
34-
import jakarta.servlet.http.HttpServletRequest;
35-
import jakarta.servlet.http.HttpServletResponse;
3636
import org.apache.commons.lang3.StringUtils;
3737
import org.apache.hc.client5.http.classic.methods.HttpGet;
3838
import org.apache.hc.client5.http.config.RequestConfig;
@@ -181,7 +181,7 @@ public UserAuthentication getOrCreateUser(App app, String accessToken) throws IO
181181
logger.info("Authentication request failed because response was missing or contained invalid JSON.");
182182
}
183183
} catch (Exception e) {
184-
logger.warn("Facebook auth request failed: GET " + PROFILE_URL + accessToken, e);
184+
logger.warn("Facebook auth request failed: GET " + PROFILE_URL + "{access_token}", e);
185185
}
186186
return SecurityUtils.checkIfActive(userAuth, user, false);
187187
});

0 commit comments

Comments
 (0)