From 0b82266882af331c692f174c77ab9c6906512b29 Mon Sep 17 00:00:00 2001 From: Dan Stillman Date: Tue, 26 Mar 2013 16:00:55 -0400 Subject: [PATCH] Don't show nsIChannel passwords in debug output --- chrome/content/zotero/xpcom/http.js | 13 +++++++++++++ chrome/content/zotero/xpcom/utilities.js | 9 +++++++++ 2 files changed, 22 insertions(+) diff --git a/chrome/content/zotero/xpcom/http.js b/chrome/content/zotero/xpcom/http.js index 34aa3b822d..d21292d0ad 100644 --- a/chrome/content/zotero/xpcom/http.js +++ b/chrome/content/zotero/xpcom/http.js @@ -13,6 +13,19 @@ Zotero.HTTP = new function() { this.xmlhttp = xmlhttp; this.status = xmlhttp.status; this.message = msg; + + // Hide password from debug output + // + // Password also shows up in channel.name (nsIRequest.name), but that's + // read-only and has to be handled in Zotero.varDump() + try { + if (xmlhttp.channel.URI.password) { + xmlhttp.channel.URI.password = "********"; + } + } + catch (e) { + Zotero.debug(e, 1); + } }; this.UnexpectedStatusException.prototype.toString = function() { diff --git a/chrome/content/zotero/xpcom/utilities.js b/chrome/content/zotero/xpcom/utilities.js index 44a7b3f01a..052b1dab2c 100644 --- a/chrome/content/zotero/xpcom/utilities.js +++ b/chrome/content/zotero/xpcom/utilities.js @@ -1136,6 +1136,9 @@ Zotero.Utilities = { } if (typeof(arr) == 'object') { // Array/Hashes/Objects + let isRequest = ((Zotero.isFx && !Zotero.isBookmarklet) || Zotero.isStandalone) + && arr instanceof Components.interfaces.nsIRequest; + //array for checking recursion //initialise at first itteration if(!parentObjects) { @@ -1145,6 +1148,12 @@ Zotero.Utilities = { for (var item in arr) { try { + // Don't display nsIRequest.name, which can contain password + if (isRequest && item == 'name') { + dumped_text += level_padding + "'" + item + "' => <>\n"; + continue; + } + var value = arr[item]; } catch(e) { dumped_text += level_padding + "'" + item + "' => <>\n";