• Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • sonar-plugin
    • None

      Sonar password is exposed on configuration page as user just has to look into DOM. SonarInstallation uses String for passwords, should use Secret.

          [JENKINS-21413] configuration page exposes sonar password

          Oliver Gondža added a comment - Fixed proposed for quite some time: https://github.com/SonarSource/jenkins-sonar-plugin/pull/9

          sbrandhof added a comment -

          Hi,
          Roadmap of Jenkins plugin is tracked in https://jira.codehaus.org/browse/SONARJNKNS, not at jenkins-ci.org
          This ticket is planned for next release: https://jira.codehaus.org/browse/SONARJNKNS-201

          sbrandhof added a comment - Hi, Roadmap of Jenkins plugin is tracked in https://jira.codehaus.org/browse/SONARJNKNS , not at jenkins-ci.org This ticket is planned for next release: https://jira.codehaus.org/browse/SONARJNKNS-201

            sonarteam Sonar Team
            ndeloof Nicolas De Loof
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: