Uploaded image for project: 'Subversion'
  1. Subversion
  2. SVN-836

password found in clear

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Duplicate
    • all
    • unscheduled
    • src
    • None
    • Linux

    Description

      I'm using Subversion alpha release from i386 rpms' 
      
      After a checkout of a "wc" repository from a webserver configured to
      "BasicAuth", the command line svn program left a username and password
      file at
      
      wc/.svn/auth/password
      wc/.svn/auth/username
      
      Inside the password file was my password in the clear.  :(
      Even worse, it was readable system wide   =:^0
      
      I deleted the file and did a 
      
      mkdir password
      chmod 400 password
      
      I was hoping that the svn client would prompt for password every
      command, but it tried to move the password directory out of the way
      and re-write my password, failed and died.
      
      I'm new around here and could not find mention of this problem in the
      issue list or task list, so my apologies if this has been tracked already.
      

      Original issue reported by bm55b

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              subversion-importer Subversion Importer
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: