[security] don't put uncrypted password in query parameters, else it may be logged on error
--- a/server/sources/native.py Mon Jul 19 15:36:16 2010 +0200
+++ b/server/sources/native.py Tue Jul 27 12:36:03 2010 +0200
@@ -1397,7 +1397,7 @@
two queries are needed since passwords are stored crypted, so we have
to fetch the salt first
"""
- args = {'login': login, 'pwd' : password}
+ args = {'login': login, 'pwd' : None}
if password is not None:
rset = self.source.syntax_tree_search(session, self._passwd_rqlst, args)
try: