[ 
https://issues.apache.org/jira/browse/TOBAGO-1904?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16512347#comment-16512347
 ] 

Hudson commented on TOBAGO-1904:
--------------------------------

SUCCESS: Integrated in Jenkins build Tobago 2.0.x #1504 (See 
[https://builds.apache.org/job/Tobago%202.0.x/1504/])
TOBAGO-1904: Password fields shouldn't render it's value (lofwyr: rev 
af7635a659de8dbb28b2b374784cc26e0768b4ce)
* (edit) 
tobago-theme/tobago-theme-standard/src/main/java/org/apache/myfaces/tobago/renderkit/html/standard/standard/tag/InRenderer.java


> Password fields shouldn't render it's value
> -------------------------------------------
>
>                 Key: TOBAGO-1904
>                 URL: https://issues.apache.org/jira/browse/TOBAGO-1904
>             Project: MyFaces Tobago
>          Issue Type: Improvement
>          Components: Themes
>            Reporter: Udo Schnurpfeil
>            Assignee: Udo Schnurpfeil
>            Priority: Major
>             Fix For: 2.1.2, 3.0.7, 4.3.0
>
>
> Because of security reasons...
> It's not a "high risk", but it will enhance the security. Some web security 
> checker test this behaviour.
> Disadvantage: If you have e.g. a registration form with password field, you 
> have to retype the password (sometime in two fields), when there is some 
> issue with the rest of the form (e.g. didn't fill a required field).
> In such a case the page design might be better, typing the password in an 
> extra step.
>  



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to