Details
-
Wish
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
ManifoldCF 1.2
-
None
Description
Currently you can see stored passwords in HTML body of the page which is quite big security hole. We could rewrite it so that the field is presented with some predefined constant string, like "###########" (only to show the field with some entered text). Then in process*Post handlers we should check if someone entered anything different here and only in such case overwrite previously stored password. When posted value is equal to "###########" - we leave previous password in configuration intact.
this applies to almost all connectors...