Closed
Bug 182693
Opened 23 years ago
Closed 22 years ago
Undo works on Password fields
Categories
(Core :: Layout: Form Controls, defect)
Tracking
()
RESOLVED
WORKSFORME
People
(Reporter: ian, Unassigned)
Details
Reproduce:
1. Type some text into a standard password box (you can use the one on
http://www.lemnet.com/ )
2. Delete the text
3. Select Edit > Undo or press CTRL + Z
Expected:
Undo is disabled and CTRL+Z doesn't do anything
Actual:
Undo replaces the password in the password box.
I'm sure you can see how this would be a security problem. For example, someone
enters their internet banking username + password in their office, remembers
they need to get their statement from another room so deletes the password. A
colleague notices this, walks over to the computer and selects Undo. Hey presto,
they are into the bank account. Quite hard to actually make happen, but possible.
| Reporter | ||
Comment 1•22 years ago
|
||
Looks like this has been resolved by another bug. Pressing undo no replaces the
password with stars.
Status: NEW → RESOLVED
Closed: 22 years ago
Resolution: --- → FIXED
Comment 2•22 years ago
|
||
If you don't know the bug that resolve it, this is WORKSFORME.
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Updated•22 years ago
|
Status: REOPENED → RESOLVED
Closed: 22 years ago → 22 years ago
Resolution: --- → WORKSFORME
You need to log in
before you can comment on or make changes to this bug.
Description
•