openmeetings / openmeetings-moodle-plugin

GNU General Public License v3.0
16 stars 8 forks source link

Errors reveal login credentials for openmeetings user #25

Closed fwsl closed 6 years ago

fwsl commented 6 years ago

Hi,

when there is a connection error to openmeetings server, plugin returns error which contains openmeetings username and password.

array ( 'url' => 'https://IP:5443/openmeetings/services/user/login?&user=USERNAME&pass=PASSWORD', 'content_type' => NULL, 'http_code' => 0, 'header_size' => 0, 'request_size' => 0, 'filetime' => -1, 'ssl_verify_result' => 1, 'redirect_count' => 0, 'total_time' => 0.04260699999999995, 'namelookup_time' => 8.8999999999999995E-5, 'connect_time' => 0.00069899999999999997, 'pretransfer_time' => 0, 'size_upload' => 0, 'size_download' => 0, 'speed_download' => 0, 'speed_upload' => 0, 'download_content_length' => -1, 'upload_content_length' => -1, 'starttransfer_time' => 0, 'redirect_time' => 0, 'redirect_url' => '', 'primary_ip' => 'IP, 'certinfo' => array ( ), 'primary_port' => 5443, 'local_ip' => 'IP', 'local_port' => 35444, )
Fault (Service error)
Request OpenMeetings! OpenMeetings Service failed and no response was returned. Additioanl info: 
Could not login User to OpenMeetings, check your OpenMeetings Module Configuration

This should never be revealed, additionally plugin should check debug and debugdisplay settings in moodle and display(or not) errors accordingly to those settings.

Cheers Grzesiek

solomax commented 6 years ago

Should be fixed, @moodlebeuth Could you please release new version(s) ?

mwuttke commented 6 years ago

Hello Maxim,

the latest version of your plugin is online.

Thanks & Greetings, Michael

solomax commented 6 years ago

Thanks a lot Michael!