Uploaded image for project: 'Runtime'
  1. Runtime
  2. RUNTIME-4274

ServerComm should only provide stack trace to allowed users

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Unresolved
    • Icon: Major Major
    • 4.9.5, 4.10.0
    • 4.9.4, 4.10.0
    • None
    • 4.10 M3

      Stack trace are useless to most users and could provide meaningful informations to an attacker. There is no reason to expose them to every users.

      The ServerComm should only return the name of the exception (and maybe the message) by default. Stack trace could still be returned for user with specific right, maybe only in dev mode.

            ggouin Guillaume Gouin
            ggouin Guillaume Gouin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: