Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Chore: Do not send user secret in the referer header #1663

Closed
wants to merge 2 commits into from

Conversation

assapir
Copy link
Contributor

@assapir assapir commented Aug 12, 2020

Until now, CLI is sending the command line args in the referer header, which might be logged.

@assapir assapir requested a review from a team August 12, 2020 10:08
@npm-deploy-user
Copy link

npm-deploy-user commented Aug 12, 2020

angular-quickstart app-large app-medium ember-quickstart react-app
prev current status prev current status prev current status prev current status prev current status
initial install 41s 31.1s 39.5s 36.4s 34.5s 31s 28.1s 20.4s 33.5s 27.7s
repeat install 9.6s 7.1s 8.6s 6.7s 8.3s 5.9s 7.7s 5.5s 9.1s 6.7s
with warm cache 32.3s 24.7s 33.8s 30.1s 31.3s 22.8s 23.4s 17.4s 29.1s 23.5s
with node_modules 9.2s 6.3s 8.6s 5.9s 9s 5.5s 7.8s 5.3s 9.4s 6.2s
with lockfile 32.6s 23.9s 31s 26.2s 29s 23.1s 21.7s 16.3s 27.4s 22.4s
with warm cache and node_modules 9.3s 6.8s 7.9s 6s 8.4s 5.4s 7.6s 5.4s 9.2s 6.3s
with warm cache and lockfile 24.7s 18.4s 26.3s 22s 24.3s 16.4s 17.8s 12.4s 21.3s 17.5s
with node_modules and lockfile 10.1s 7.3s 9.8s 7s 8.6s 6.7s 7.8s 5.7s 9.7s 7.2s

.gitignore Outdated Show resolved Hide resolved
@assapir assapir requested review from darcyclarke and a team August 13, 2020 05:27
@rami548
Copy link

rami548 commented Apr 16, 2021

@natester605 natester605 mentioned this pull request Sep 25, 2021
@nlf nlf deleted the assapir/redact-password branch March 28, 2022 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Enhancement new feature or improvement Release 6.x work is associated with a specific npm 6 release semver:patch semver patch level for changes
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

5 participants