Uploaded image for project: 'Tapestry 5'
  1. Tapestry 5
  2. TAP5-87

PasswordField should not update its value parameter when the submitted value is blank

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 5.0.15
    • 5.0.16
    • None
    • None

    Description

      Currently, the PasswordField component does not display it's value. Although this indeed represents best practices in handling passwords (e.g. if the password field did display its value although masked, it would still be visible in the source), the current behavior stumps new users and unnecessarily enforces a particular process (e.g. never display the password) or forces a user to split page containing the password field (e.g. what would have other in orderwise been a single page to create and update a value, now has to be two different pages) to avoid validation issues.

      The requested parameter (e.g. "displayValue") would contain a warning in bold that displaying the password value could be a security issue (and potentially log a warning). The default value of the parameter should be "false", that is it wouldn't display the password, unless explicitly enabled.

      Attachments

        Activity

          People

            hlship Howard Lewis Ship
            akochnev Alex Kotchnev
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: