Bug 1010031 - Installer displays overlord password in plain text in UI
Summary: Installer displays overlord password in plain text in UI
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: JBoss Fuse Service Works 6
Classification: JBoss
Component: Installer
Version: 6.0.0 GA
Hardware: Unspecified
OS: Unspecified
unspecified
urgent
Target Milestone: ER4
: ---
Assignee: Thomas Hauser
QA Contact: Len DiMaggio
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-09-19 18:21 UTC by Len DiMaggio
Modified: 2014-02-06 15:26 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-02-06 15:26:38 UTC
Type: Bug


Attachments (Terms of Use)
Screenshot (83.93 KB, image/png)
2013-09-19 18:22 UTC, Len DiMaggio
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1010045 0 unspecified CLOSED Installer refers to "overlord" - can we change this to "JBoss DTGov"? 2021-02-22 00:41:40 UTC

Internal Links: 1010045

Description Len DiMaggio 2013-09-19 18:21:48 UTC
Description of problem:

See the attached screenshot - we should never display a password in plaintext in a UI.

Version-Release number of selected component (if applicable):
ER3 installer

How reproducible:
100%

Steps to Reproduce:
1. Run the installer
2.
3.

Actual results:


Expected results:


Additional info:

Comment 1 Len DiMaggio 2013-09-19 18:22:47 UTC
Created attachment 800050 [details]
Screenshot

Comment 2 Thomas Hauser 2013-09-19 18:31:39 UTC
The requirement for needing this password to even be gathered at all was revealed on Monday. Changing the way izpack displays given variables requires 
modifications to IzPack. 

Additional issues: There is a double ":" in the String giving the user-name.

Comment 3 Len DiMaggio 2013-10-04 19:49:19 UTC
Verified in the Oct 4 ER4 respin #2 build.


Note You need to log in before you can comment on or make changes to this bug.