Greetings!

Is it by design that passwords are stored unencrypted in the
database/repository? Specifically "event.last-sync-pw".

Basically, I was trying to sync/pull from another team member using the
https protocol (his server was configured using apache cgi-bin).  There was
an error during the transfer, but it did seem that the data was received.
Later, I was poking around the repository database using sqlite3 and saw my
password.

Is this a bug?  If not, may I make a request that if the password must be
stored that it is encrypted?


Thanks for a great program!

Zakero
_______________________________________________
fossil-users mailing list
[email protected]
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to