YunoHost-Apps / borg_ynh

An experimental Borg implementation for YunoHost
https://www.borgbackup.org/
GNU Affero General Public License v3.0
19 stars 22 forks source link

[security] BORG_PASSPHRASE is not removed when sharing logs #87

Closed fflorent closed 3 years ago

fflorent commented 3 years ago

When a backup fails and we share logs with yunopaste, the BORG_PASSPHRASE is output in clear.

It would be worth to remove it (replace with some dummy password).

Also could be worth to also anonymize the distant repo:

image

Thanks!

zamentur commented 3 years ago

It has been fixed in unstable ynh version, will be available in next YNH version https://github.com/YunoHost/yunohost/commit/dbe5e51ef134889ba385d84b08a69c249daa9c5e