Skip to content

Commit fd0ef5c

Browse files
authored
Tokens are a risk to display on an unprotected system (#765)
1 parent 33210e3 commit fd0ef5c

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

appengine-java8/gaeinfo/src/main/java/com/example/appengine/standard/GaeInfoServlet.java

+4-2
Original file line numberDiff line numberDiff line change
@@ -53,14 +53,16 @@ public class GaeInfoServlet extends HttpServlet {
5353
"/computeMetadata/v1/instance/service-accounts/default/aliases",
5454
"/computeMetadata/v1/instance/service-accounts/default/",
5555
"/computeMetadata/v1/instance/service-accounts/default/scopes",
56-
"/computeMetadata/v1/instance/service-accounts/default/token",
56+
// Tokens work - but are a security risk to display
57+
// "/computeMetadata/v1/instance/service-accounts/default/token"
5758
};
5859

5960
final String[] v1Acct = {
6061
"/computeMetadata/v1/instance/service-accounts/{account}/aliases",
6162
"/computeMetadata/v1/instance/service-accounts/{account}/email",
6263
"/computeMetadata/v1/instance/service-accounts/{account}/scopes",
63-
"/computeMetadata/v1/instance/service-accounts/{account}/token"
64+
// Tokens work - but are a security risk to display
65+
// "/computeMetadata/v1/instance/service-accounts/{account}/token"
6466
};
6567

6668
final String metadata = "http://metadata.google.internal";

0 commit comments

Comments
 (0)