Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-1650

[7.2.z] Disable auto completion for user account New Password and Password Confirmation fields

    XMLWordPrintable

Details

    • Hide
      1. Login to admin console
      2. Create realm "myRealm"
      3. Create a new user and set credentials eg. test@123 from Credentials tab
      4. Logout and try again to set the same credentials for the user mentioned above the browser proposes already set password.
      Show
      Login to admin console Create realm "myRealm" Create a new user and set credentials eg. test@123 from Credentials tab Logout and try again to set the same credentials for the user mentioned above the browser proposes already set password.

    Description

      In the credentials-tab of user management the password fields are of type text i.e <input .... type="text".../> causing the browser to propose already used password.

      This is critical from a security perspective.

      To overcome this autocomplete must be set to off for New Password and Password Confirmation fields.

      Attachments

        Activity

          People

            ssilvert@redhat.com Stan Silvert
            rhn-support-sshriram Saurabh Shriramwar (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: