TFS plugin: credentials password is in clear text in page source =-O

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: Critical
    • Component/s: tfs-plugin
    • Environment:
      Linux
      Windows

      When using Team Foundation Server plugin in Source Control Management section, the entered password can be viewed by anyone by looking into the page source.

      Suggestion: after the entry of the password, encrypt the password and store it in the file system. Do not show the password in the password field afterwards; instead, show a placeholder/marker message like <Password Is Encryped>.

            Assignee:
            redsolo
            Reporter:
            Vladimir Dyuzhev
            Votes:
            4 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: