Maven
  1. Maven
  2. MNG-4459

[regression] Effective settings as visible to plugins contain plain text passwords

    Details

    • Type: Bug Bug
    • Status: Closed Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 3.0-alpha-4
    • Fix Version/s: 3.0-alpha-5
    • Component/s: Settings
    • Labels:
      None
    • Complexity:
      Intermediate
    • Number of attachments :
      0

      Description

      When we introduced MNG-553, the passwords were only decrypted at the transport layer and the Settings instance kept in memory was kept encrypted. E.g. to save plugins from accidentally dumping the plain text passwords on the console or such.

      This does currently not hold for 3.0-alpha-4 as org.apache.maven.plugin:maven-help-plugin:2.0:effective-settings shows.

        Issue Links

          Activity

          Benjamin Bentmann made changes -
          Field Original Value New Value
          Link This issue is related to MNG-553 [ MNG-553 ]
          Benjamin Bentmann made changes -
          Assignee Benjamin Bentmann [ bentmann ]
          Fix Version/s 3.0-alpha-5 [ 14952 ]
          Resolution Fixed [ 1 ]
          Status Open [ 1 ] Closed [ 6 ]

            People

            • Assignee:
              Benjamin Bentmann
              Reporter:
              Benjamin Bentmann
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: