From 4a934c57b005fc272e0afa3537f04e4206b78090 Mon Sep 17 00:00:00 2001 From: Andrew McMillan Date: Fri, 25 Nov 2011 08:18:44 +1300 Subject: [PATCH] Remove password from LDAP log messages. --- inc/drivers_ldap.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/inc/drivers_ldap.php b/inc/drivers_ldap.php index 0712670a..daeb8780 100644 --- a/inc/drivers_ldap.php +++ b/inc/drivers_ldap.php @@ -212,12 +212,12 @@ class ldapDrivers } else if ( empty($passwd) || preg_match('/[\x00-\x19]/',$passwd) ) { // See http://www.php.net/manual/en/function.ldap-bind.php#73718 for more background - dbg_error_log( 'LDAP', 'drivers_ldap : user %s supplied empty or invalid password (%s): login rejected', $dnUser, $passwd ); + dbg_error_log( 'LDAP', 'drivers_ldap : user %s supplied empty or invalid password: login rejected', $dnUser ); return false; } else { if ( !@ldap_bind($this->connect, $dnUser, $passwd) ) { - dbg_error_log( "LDAP", "drivers_ldap : Failed to bind to user %s using password %s", $dnUser, $passwd ); + dbg_error_log( "LDAP", "drivers_ldap : Failed to bind to user %s ", $dnUser ); return false; } } -- 2.11.4.GIT