ofbiz-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Michael Brohl (JIRA)" <j...@apache.org>
Subject [jira] [Reopened] (OFBIZ-9471) Set autocomplete to off for all the password fields.
Date Tue, 11 Jul 2017 10:58:00 GMT

     [ https://issues.apache.org/jira/browse/OFBIZ-9471?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Michael Brohl reopened OFBIZ-9471:
----------------------------------

Not sure if we back port this one (is it a bug or improvement). I'll reopen and let Arun decide.

> Set autocomplete to off for all the password fields.
> ----------------------------------------------------
>
>                 Key: OFBIZ-9471
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-9471
>             Project: OFBiz
>          Issue Type: Bug
>          Components: framework
>            Reporter: Ritesh Kumar
>            Assignee: Arun Patidar
>            Priority: Minor
>             Fix For: Upcoming Release
>
>         Attachments: OFBIZ-9471-FRAMEWORK.patch, OFBIZ-9471-PLUGIN.patch
>
>
> The login and Forget password screens have password inputs. It is a best practice to
disable autocomplete on the password field as it will avoid caching sensitive data on client
site (CC numbers) and avoid storing the password in an insecure and hackable client-site database.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

Mime
View raw message