[ 
https://issues.apache.org/jira/browse/FELIX-6570?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17616404#comment-17616404
 ] 

Carsten Ziegeler commented on FELIX-6570:
-----------------------------------------

[~sagarmiglani] Thanks, I think your patch goes into the right direction - 
there are a couple of things to consider. The metatype support is optional 
(metatype bundle might not be deployed) so WebConsolePlugin should not 
important any class from metatype and everything should be done in the optional 
metatype support class (if available).
For pid handling - there can be more than one pid and best to check all of them 
for passwords.

[~laeubi] While private properties should be used for it, it is not common 
practice. And the reverse is also not necessarily truy that every private 
property is a secret.

> Components webconsole-plugin shows password in clear text
> ---------------------------------------------------------
>
>                 Key: FELIX-6570
>                 URL: https://issues.apache.org/jira/browse/FELIX-6570
>             Project: Felix
>          Issue Type: Bug
>          Components: Web Console
>    Affects Versions: webconsole-ds-plugin-2.1.0
>            Reporter: Sagar Miglani
>            Priority: Major
>         Attachments: Screenshot 2022-05-09 at 4.48.42 PM.png, 
> webconsole-plugins.patch
>
>
> Open a component details page (eg: 
> localhost:8080/system/console/components/${componentId}) for a component with 
> a Password Property.
> Passwords are shown in clear text. [^Screenshot 2022-05-09 at 4.48.42 PM.png]



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to