密码明文放日志里,安全真的不重要吗
kelby opened this issue · 2 comments
kelby commented
Started POST "/admin/sessions?password=admin&username=admin" for 127.0.0.1 at 2014-06-08 21:24:43 +0800
Processing by Admin::SessionsController#create as JSON
Parameters: {"password"=>"admin", "username"=>"admin"}
Completed 200 OK in 1ms (Views: 0.2ms)
我没用过 angularjs,但无论什么技术,密码都不应该出现在日志里啊。并且还是明文 ...