From 316fcc612684a83eefd5b1d4722b00ae6d6453b3 Mon Sep 17 00:00:00 2001 From: Jesse Suen Date: Thu, 27 Sep 2018 03:42:19 -0700 Subject: [PATCH] Fix issue where argocd-server logged credentials in plain text during repo add (issue #653) --- server/server.go | 2 ++ 1 file changed, 2 insertions(+) diff --git a/server/server.go b/server/server.go index f44b817884..00677fefd3 100644 --- a/server/server.go +++ b/server/server.go @@ -367,6 +367,8 @@ func (a *ArgoCDServer) newGRPCServer() *grpc.Server { sensitiveMethods := map[string]bool{ "/session.SessionService/Create": true, "/account.AccountService/UpdatePassword": true, + "/repository.RepositoryService/Create": true, + "/repository.RepositoryService/Update": true, } // NOTE: notice we do not configure the gRPC server here with TLS (e.g. grpc.Creds(creds)) // This is because TLS handshaking occurs in cmux handling