You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Sep 18, 2021. It is now read-only.
Scrubbing of sensitive information in TokenRequestValidationLog is case-sensitive. This can cause an issue with the ResourceOwner flow when a user provides invalid credentials and the client posting the credentials does not match a fieldname exactly. So if the fieldname is "Password" instead of "password", the password is not scrubbed and is leaked to the log.
The text was updated successfully, but these errors were encountered:
Scrubbing of sensitive information in TokenRequestValidationLog is case-sensitive. This can cause an issue with the ResourceOwner flow when a user provides invalid credentials and the client posting the credentials does not match a fieldname exactly. So if the fieldname is "Password" instead of "password", the password is not scrubbed and is leaked to the log.
The text was updated successfully, but these errors were encountered: