[ 
https://issues.apache.org/jira/browse/TAPESTRY-2637?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12627947#action_12627947
 ] 

Ulrich Stärk commented on TAPESTRY-2637:
----------------------------------------

I believe a better approach would be to leave the behaviour as it is but change 
the way passwordfield handles blank input. Right now it updates the value to 
blank an thus causes validation issues or blanks a formerly set password. It 
should contain some logic to see whether a value is set and only update this 
value (and cause validation) when the user actually enters something.

> Add a parameter to PasswordField component to populate the password value
> -------------------------------------------------------------------------
>
>                 Key: TAPESTRY-2637
>                 URL: https://issues.apache.org/jira/browse/TAPESTRY-2637
>             Project: Tapestry
>          Issue Type: Improvement
>          Components: tapestry-core
>    Affects Versions: 5.0.15
>            Reporter: Alex Kotchnev
>             Fix For: 5.0.15
>
>
> Currently, the PasswordField component does not display it's value. Although 
> this indeed represents best practices in handling passwords (e.g. if the 
> password field did display its value although masked, it would still be 
> visible in the source), the current behavior stumps new users and 
> unnecessarily enforces a particular process (e.g. never display the password) 
> or forces a user to split page containing the password field (e.g. what would 
> have other in orderwise been a single page to create and update a value, now 
> has to be two different pages) to avoid validation issues. 
> The requested parameter (e.g. "displayValue") would contain a warning in bold 
> that displaying the password value could be a security issue (and potentially 
> log a warning). The default value of the parameter should be "false", that is 
> it wouldn't display the password, unless explicitly enabled. 

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to