-
Notifications
You must be signed in to change notification settings - Fork 2.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Mail password configuration not secured #1850
Comments
I can see how this would be an issue if you were using your Gmail account to send mail. Usually this password is for an API / robot account so the password is less sensitive. Presenting the password with stars would still make it possible to see the underlying password by viewing the source. We would have to empty the field instead, this can sometimes make it look like it hasn't been populated. |
Closing in favour of #1061 |
A field widget that allows for entering of sensitive information that can be revealed at the user's request - ie. API keys, secrets. When a sensitive field that has been previously populated is loaded again, a placeholder is used instead of the real value, until the user opts to reveal the value. The real value is loaded via AJAX. Credit to @tomaszstrojny for the original implementation. Replaces #5062. Fixes #5061, #1850, perhaps #1061. Co-authored-by: Tomasz Strojny <tomasz@init.biz>
A field widget that allows for entering of sensitive information that can be revealed at the user's request - ie. API keys, secrets. When a sensitive field that has been previously populated is loaded again, a placeholder is used instead of the real value, until the user opts to reveal the value. The real value is loaded via AJAX. Credit to @tomaszstrojny for the original implementation. Replaces #5062. Fixes #5061, #1850, perhaps #1061. Co-authored-by: Tomasz Strojny <tomasz@init.biz> Co-authored-by: Luke Towers <github@luketowers.ca>
Fixed by #5201. |
Hi all,
One thing I noticed today was that the password in Settings --> Mail Configuration --> Password, the password is visible in plain text. I think it (at least) desirable that the password here is presented in stars (*******).
I have made a (edited) screenshot:
data:image/s3,"s3://crabby-images/fbe26/fbe26b8ce15584140420c791dd08542ae5a3a7e0" alt="Image of problem"
I think this is a serious issue as a personal email password can be viewed by all persons who can acces this particular back-end account (like the web-developer).
The text was updated successfully, but these errors were encountered: