aboutsummaryrefslogtreecommitdiffstats
path: root/Mailman/Cgi/private.py
diff options
context:
space:
mode:
authorMark Sapiro <mark@msapiro.net>2018-06-11 09:59:26 -0700
committerMark Sapiro <mark@msapiro.net>2018-06-11 09:59:26 -0700
commitd363c183a208a1ef34847656533cb818d7a7cf50 (patch)
tree1481f31598316e141fba03af3e549b28fbef349b /Mailman/Cgi/private.py
parent0c2912a8d2a295a00260262cf6b7c01559d368b0 (diff)
parent540452e22108455e4efebc8fa7340760a68607f7 (diff)
downloadmailman2-d363c183a208a1ef34847656533cb818d7a7cf50.tar.gz
mailman2-d363c183a208a1ef34847656533cb818d7a7cf50.tar.xz
mailman2-d363c183a208a1ef34847656533cb818d7a7cf50.zip
Implement security log.
Diffstat (limited to '')
-rwxr-xr-xMailman/Cgi/private.py7
1 files changed, 7 insertions, 0 deletions
diff --git a/Mailman/Cgi/private.py b/Mailman/Cgi/private.py
index 80369e84..131c5de8 100755
--- a/Mailman/Cgi/private.py
+++ b/Mailman/Cgi/private.py
@@ -142,6 +142,13 @@ def main():
if cgidata.has_key('submit'):
# This is a re-authorization attempt
message = Bold(FontSize('+1', _('Authorization failed.'))).Format()
+ remote = os.environ.get('HTTP_FORWARDED_FOR',
+ os.environ.get('HTTP_X_FORWARDED_FOR',
+ os.environ.get('REMOTE_ADDR',
+ 'unidentified origin')))
+ syslog('security',
+ 'Authorization failed (private): user=%s: list=%s: remote=%s',
+ username, listname, remote)
# give an HTTP 401 for authentication failure
print 'Status: 401 Unauthorized'
# Are we processing a password reminder from the login screen?