• Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • sonar-plugin
    • None

      Sonar password is exposed on configuration page as user just has to look into DOM. SonarInstallation uses String for passwords, should use Secret.

          [JENKINS-21413] configuration page exposes sonar password

          Nicolas De Loof created issue -

          Oliver Gondža added a comment - Fixed proposed for quite some time: https://github.com/SonarSource/jenkins-sonar-plugin/pull/9

          sbrandhof added a comment -

          Hi,
          Roadmap of Jenkins plugin is tracked in https://jira.codehaus.org/browse/SONARJNKNS, not at jenkins-ci.org
          This ticket is planned for next release: https://jira.codehaus.org/browse/SONARJNKNS-201

          sbrandhof added a comment - Hi, Roadmap of Jenkins plugin is tracked in https://jira.codehaus.org/browse/SONARJNKNS , not at jenkins-ci.org This ticket is planned for next release: https://jira.codehaus.org/browse/SONARJNKNS-201
          sbrandhof made changes -
          Resolution New: Duplicate [ 3 ]
          Status Original: Open [ 1 ] New: Closed [ 6 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 153279 ] New: JNJira + In-Review [ 207339 ]

            sonarteam Sonar Team
            ndeloof Nicolas De Loof
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: