Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-1650

[7.2.z] Disable auto completion for user account New Password and Password Confirmation fields

XMLWordPrintable

    • Hide
      1. Login to admin console
      2. Create realm "myRealm"
      3. Create a new user and set credentials eg. test@123 from Credentials tab
      4. Logout and try again to set the same credentials for the user mentioned above the browser proposes already set password.
      Show
      Login to admin console Create realm "myRealm" Create a new user and set credentials eg. test@123 from Credentials tab Logout and try again to set the same credentials for the user mentioned above the browser proposes already set password.

      In the credentials-tab of user management the password fields are of type text i.e <input .... type="text".../> causing the browser to propose already used password.

      This is critical from a security perspective.

      To overcome this autocomplete must be set to off for New Password and Password Confirmation fields.

              ssilvert@redhat.com Stan Silvert
              rhn-support-sshriram Saurabh Shriramwar (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: