mirror of
https://github.com/etcd-io/etcd.git
synced 2024-09-27 06:25:44 +00:00
etcdserver: don't let InternalAuthenticateRequest have password (#11818)
This commit is contained in:
parent
035e1db0a2
commit
feb56298dd
@ -441,9 +441,10 @@ func (s *EtcdServer) Authenticate(ctx context.Context, r *pb.AuthenticateRequest
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// internalReq doesn't need to have Password because the above s.AuthStore().CheckPassword() already did it.
|
||||||
|
// In addition, it will let a WAL entry not record password as a plain text.
|
||||||
internalReq := &pb.InternalAuthenticateRequest{
|
internalReq := &pb.InternalAuthenticateRequest{
|
||||||
Name: r.Name,
|
Name: r.Name,
|
||||||
Password: r.Password,
|
|
||||||
SimpleToken: st,
|
SimpleToken: st,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user