Last modified: 2007-06-03 01:57:12 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T10931, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 8931 - Password repeated in HTML page if login unsucessful
Password repeated in HTML page if login unsucessful
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
User login and signup (Other open bugs)
unspecified
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
http://en.wikipedia.org/w/index.php?t...
:
Depends on:
Blocks: 9816
  Show dependency treegraph
 
Reported: 2007-02-09 17:50 UTC by S. Ali Tokmen
Modified: 2007-06-03 01:57 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
Values of password fields cleared (982 bytes, patch)
2007-03-06 17:10 UTC, Felix Reimann
Details

Description S. Ali Tokmen 2007-02-09 17:50:09 UTC
Hello

When you try to log in to the Wikipedia web site, if you mistype the password or
the user name than the user name and password is written back.

Thought repeating the password field as well makes us one field less when we
don't type our user name correctly, I think it is a big security problem to put
it in the web page. Perhaps not replying would be the best.

To try:

    Go to the Wikipedia login page
    Mistype your user name or password (or both)
    The page saying "login error" comes. Now right click on the page and say
"view source".
    Look for the string "password", and you'll see the types password appears in
the web page.

Thank you
Comment 1 Felix Reimann 2007-03-06 17:10:17 UTC
Created attachment 3301 [details]
Values of password fields cleared
Comment 2 S. Ali Tokmen 2007-03-06 19:28:10 UTC
Verified.

Thank you
Comment 3 Rob Church 2007-03-06 19:30:35 UTC
Reopening bug; fix not committed to source control.
Comment 4 Daniel Cannon (AmiDaniel) 2007-06-03 01:57:12 UTC
Committed as r22665.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links