Skip to content

Commit 8d0758c

Browse files
committed
MAGETWO-52371: Marketplace credentials are exposed via URL
- removal of password from json response.
1 parent 8bc4691 commit 8d0758c

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

setup/src/Magento/Setup/Controller/Marketplace.php

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -90,12 +90,12 @@ public function checkAuthAction()
9090
);
9191
$isValid = json_decode($isValid, true);
9292
if ($isValid['success'] === true) {
93-
return new JsonModel(['success' => true, 'data' => $authDataJson]);
93+
return new JsonModel(['success' => true, 'data' => ['username' => $authDataJson['username']]]);
9494
} else {
9595
return new JsonModel(['success' => false, 'message' => $isValid['message']]);
9696
}
9797
}
98-
return new JsonModel(['success' => false, 'data' => $authDataJson]);
98+
return new JsonModel(['success' => false, 'data' => ['username' => $authDataJson['username']]]);
9999
} catch (\Exception $e) {
100100
return new JsonModel(['success' => false, 'message' => $e->getMessage()]);
101101
}

0 commit comments

Comments
 (0)