When a password-protected FTP or HTTP resource is accessed via ftp://user:password@host/ method, and then printed, the password is printed as part of the URL. This creates a security risk, as the user does not notice that his or her password is printed along with the page, and may share or submit the hardcopy (with the password) to an untrusted third party. Steps to reproduce: 1. Go to a ftp://user:password@host/dir/file URL. 2. Print the file (or do a print preview). 3. See the password in the printed page. Expected results: Password is masked or removed entirely. Actual results: Secret password revealed in printed material.
nsbeta1+ -> jkeiser
Can someone point me to the code which deals with putting the URL on the printed page?
Confirming in 1.4.1/1.5 release versions / win32.
This bug seems still be present in Mozilla Firefox 1.0 Win
My guess is that the code that would need to be changed lies in: http://lxr.mozilla.org/mozilla/source/layout/printing/nsPrintEngine.cpp#2077
*** Bug 278513 has been marked as a duplicate of this bug. ***
Bug 280438 is similar and is blocking aviary1.1
(In reply to comment #6) > http://lxr.mozilla.org/mozilla/source/layout/printing/nsPrintEngine.cpp#2077 Alternatively, we can fix two implementations of them. Are ftp and http(s) the only schemes we have to worry about?
too late for 1.8b1, but we should get this for 1.8b2.
it seems that there are 3 situations. if u put the username and password in the address bar, the username and password shows up at the top of the printed page. if u only put the username in the address bar and fill in the alert box with ur password, only ur username appears on the printed page. if u put neither in the address bar and fill in the alert box with both, neither appear at the top of the printed page. so its not putting ur username and password at the top.. per se. its just putting whatever u put in the address bar. temporary fix, dont put ur username and password in the address bar. just fill in the alert box.
Created attachment 177401 [details] [diff] [review] Simple fix
13 years ago
Comment on attachment 177401 [details] [diff] [review] Simple fix r=jst
*** Bug 292876 has been marked as a duplicate of this bug. ***