Bug 1508994 - APBs should not display passwords as text.
Summary: APBs should not display passwords as text.
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Service Broker
Version: 3.7.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: 3.7.0
Assignee: cchase
QA Contact: Weihua Meng
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-11-02 16:00 UTC by cchase
Modified: 2017-11-28 22:21 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
undefined
Clone Of:
Environment:
Last Closed: 2017-11-28 22:21:23 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:3188 0 normal SHIPPED_LIVE Moderate: Red Hat OpenShift Container Platform 3.7 security, bug, and enhancement update 2017-11-29 02:34:54 UTC

Description cchase 2017-11-02 16:00:33 UTC
Description of problem:
Passwords in APBs for MediaWiki, Postgres, MySQL, and MariaDB are currently showing passwords in plain text as you type them in.  They should use display_type: password in order to use a double entry with confirmation.

Version-Release number of selected component (if applicable):


How reproducible:
100%


Steps to Reproduce:
1. Login to the web console
2. Select for provision either PostgreSQL (APB), MariaDB (APB), MySql (APB), or MediaWiki (APB) 
3. 

Actual results:
password fields show in plain text

Expected results:
A double entry field with confirmation is shown.  If a field is required, it the user cannot progress without entering both matching fields.  If a field is not required, both fields can be left blank but must match.

Comment 4 Yadan Pei 2017-11-07 05:50:15 UTC
Checked following APBs:

PostgreSQL (APB)
MySQL (APB)
Mediawiki (APB)
MariaDB (APB)

When a fields type is password, an additional Retype option will be provided to request confirmation.


Could be verified when ON_QA

Comment 5 Weihua Meng 2017-11-09 06:22:52 UTC
Fixed.

openshift3/mediawiki-apb:v3.7.0-0.198.0.3
openshift3/mariadb-apb:v3.7.0-0.198.0.3
openshift3/mysql-apb:v3.7.0-0.198.0.3
openshift3/postgresql-apb:v3.7.0-0.198.0.3

Comment 8 errata-xmlrpc 2017-11-28 22:21:23 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2017:3188


Note You need to log in before you can comment on or make changes to this bug.