Details

      Description

      Currently you can see stored passwords in HTML body of the page which is quite big security hole. We could rewrite it so that the field is presented with some predefined constant string, like "###########" (only to show the field with some entered text). Then in process*Post handlers we should check if someone entered anything different here and only in such case overwrite previously stored password. When posted value is equal to "###########" - we leave previous password in configuration intact.

      this applies to almost all connectors...

        Attachments

          Activity

            People

            • Assignee:
              kwright@metacarta.com Karl Wright
              Reporter:
              redguy666 Maciej Lizewski
            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: