If you upgrade to the 2.0 releases, all passwords will be encrypted. I know
it's not trivial, and maybe we can backport that to a 1.7 release, but as we're
about to start on the 2.5 betas, we're unlikely to continue making major
changes to 1.7 from here on out. We'll see what we can do though.
Christian Hammond - christ...@beanbaginc.com
Review Board - https://www.reviewboard.org
Beanbag, Inc. - https://www.beanbaginc.com
From: Alfred von Campe <alf...@von-campe.com>
Reply: firstname.lastname@example.org <email@example.com>>
Date: February 20, 2015 at 12:07:29 PM
To: firstname.lastname@example.org <email@example.com>>
Subject: Subversion access via https:// and plaintext passwords
> We have been using ReviewBoard with our Subversion repos using svn+ssh://
> access, and
> while functional, it’s been a little slow. Performance with https:// access
> to our Subversion
> servers is noticeably faster, but when I configure the Repository in
> ReviewBoard and
> specify the username and password to use, I noticed that the password is
> stored in plain
> text in the database. The database itself is not easily accessible by users,
> but the nightly
> database dumps could be read by others, so I am concerned about a possible
> exposure of
> automated build user account password.
> We are still using ReviewBoard 1.7.27 as it is hosted on a CentOS 6 server,
> so upgrading
> to 2.X is not trivial. Is it common practice for ReviewBoard users to store
> passwords in the database in plain text?
> Supercharge your Review Board with Power Pack:
> Want us to host Review Board for you? Check out RBCommons:
> Happy user? Let us know! https://www.reviewboard.org/users/
> You received this message because you are subscribed to the Google Groups
> To unsubscribe from this group and stop receiving emails from it, send an
> email to reviewboard+unsubscr...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Supercharge your Review Board with Power Pack:
Want us to host Review Board for you? Check out RBCommons:
Happy user? Let us know! https://www.reviewboard.org/users/
You received this message because you are subscribed to the Google Groups
To unsubscribe from this group and stop receiving emails from it, send an email
For more options, visit https://groups.google.com/d/optout.