Uploaded image for project: 'Tools (JBoss Tools)'
  1. Tools (JBoss Tools)
  2. JBIDE-17973

Application wizard, embed wizard: Obscure database password

XMLWordPrintable

      When creating an OpenShift application with a database cartridge, the database password is shown in clear text. This password should be obscured.

      It was noted that OpenShift does show clear text passwords in some locations, the difference here is that the user did not prompt for this information meaning we are displaying a password in clear text at a potential point where the user is not aware they need to be in a 'secure' environment.

      Reproduce steps:
      1. Open new OpenShift Application wizard
      2. Sign in & proceed to next screen
      3. Choose application cartridge (JBoss EAP 6 for instance) & proceed to next screen
      4. Add embedded cartridge for database (mySQL 5.5 for instance) & proceed to next screen
      5. Click next on set up project screen
      6. Click finish on next screen
      7 -> ISSUE HERE. Once app is created, pop-up is shown with mySQL database password shown in clear text. Screenshot: https://www.evernote.com/shard/s230/sh/cd8123fb-a400-4699-ad08-bcbc06f7b5d5/5513a009f80cfb4099ba4dd0c5640212

      Expected: Password on this pop-up should be obscured.

            manderse@redhat.com Max Andersen
            crobson@redhat.com Catherine Weeks
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: