[Twisted-Python] Re: [Twisted-commits] "no such user" is too informative, no need to give attackers more information than necessary

itamarst CVS wrote:
While there is good motivation for not making this public info, it seems like it would be a good thing to make this available to someone debugging the system, either by way of the log file or some other means. While not necessarily appropriate for Twisted, one approach that I've used well in the past (in my own webserver and web app software) was to have an error page that recognized authenticated users and would display generic errors to unknown or unauthorized users, and informative/descriptive errors to authorized people (as well as direct access to the web-based tools used to determine what went wrong and so on). Maybe some sort of policy framework might let that happen within Twisted or some other generalized logging infrastructure. But at the least, it seems like this sort of info should be logged. Cheers, - Bruce

It would already be helpful if there was a simple log entry, console message etc. about this On Monday 28 April 2003 01:41 pm, Bruce Mitchener wrote:
-- UC -- Open Source Solutions 4U, LLC 2570 Fleetwood Drive Phone: +1 650 872 2425 San Bruno, CA 94066 Cell: +1 650 302 2405 United States Fax: +1 650 872 2417

It would already be helpful if there was a simple log entry, console message etc. about this On Monday 28 April 2003 01:41 pm, Bruce Mitchener wrote:
-- UC -- Open Source Solutions 4U, LLC 2570 Fleetwood Drive Phone: +1 650 872 2425 San Bruno, CA 94066 Cell: +1 650 302 2405 United States Fax: +1 650 872 2417
participants (2)
-
Bruce Mitchener
-
Uwe C. Schroeder