From 99a90c34a0811c7a856bf926744b8fce63a516c5 Mon Sep 17 00:00:00 2001 From: Rodrigo Zambrana Date: Thu, 2 Jan 2025 16:45:36 -0300 Subject: [PATCH] Change this code to not log user-controlled data. --- .../lacnic/elections/ejb/impl/ElectionsManagerEJBBean.java | 4 ---- 1 file changed, 4 deletions(-) diff --git a/elections-ejb/src/main/java/net/lacnic/elections/ejb/impl/ElectionsManagerEJBBean.java b/elections-ejb/src/main/java/net/lacnic/elections/ejb/impl/ElectionsManagerEJBBean.java index 209da4d..174da1e 100644 --- a/elections-ejb/src/main/java/net/lacnic/elections/ejb/impl/ElectionsManagerEJBBean.java +++ b/elections-ejb/src/main/java/net/lacnic/elections/ejb/impl/ElectionsManagerEJBBean.java @@ -155,12 +155,8 @@ private boolean parseCaptchaResponse(String response) { public boolean isValidCaptchaResponse(String reCaptchaResponse) { try (CloseableHttpClient httpClient = HttpClients.createDefault();) { appLogger.info("Start verifying reCAPTCHA response"); - appLogger.info("reCAPTCHA response value: " + reCaptchaResponse); String skGoogleApiReCaptcha = EJBFactory.getInstance().getElectionsParametersEJB().getParameter(Constants.SK_GOOGLE_API_RECAPTCHA); - String checkURL = "https://www.google.com/recaptcha/api/siteverify" + "?secret=" + skGoogleApiReCaptcha + "&response=" + reCaptchaResponse; - - appLogger.info("Check URL: " + checkURL); HttpPost post = new HttpPost("https://www.google.com/recaptcha/api/siteverify");