Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1508994 - APBs should not display passwords as text.
APBs should not display passwords as text.
Status: CLOSED ERRATA
Product: OpenShift Container Platform
Classification: Red Hat
Component: Service Broker (Show other bugs)
3.7.0
Unspecified Unspecified
unspecified Severity unspecified
: ---
: 3.7.0
Assigned To: cchase
Weihua Meng
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-02 12:00 EDT by cchase
Modified: 2017-11-28 17:21 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: No Doc Update
Doc Text:
undefined
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-11-28 17:21:23 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:3188 normal SHIPPED_LIVE Moderate: Red Hat OpenShift Container Platform 3.7 security, bug, and enhancement update 2017-11-28 21:34:54 EST

  None (edit)
Description cchase 2017-11-02 12:00:33 EDT
Description of problem:
Passwords in APBs for MediaWiki, Postgres, MySQL, and MariaDB are currently showing passwords in plain text as you type them in.  They should use display_type: password in order to use a double entry with confirmation.

Version-Release number of selected component (if applicable):


How reproducible:
100%


Steps to Reproduce:
1. Login to the web console
2. Select for provision either PostgreSQL (APB), MariaDB (APB), MySql (APB), or MediaWiki (APB) 
3. 

Actual results:
password fields show in plain text

Expected results:
A double entry field with confirmation is shown.  If a field is required, it the user cannot progress without entering both matching fields.  If a field is not required, both fields can be left blank but must match.
Comment 4 Yadan Pei 2017-11-07 00:50:15 EST
Checked following APBs:

PostgreSQL (APB)
MySQL (APB)
Mediawiki (APB)
MariaDB (APB)

When a fields type is password, an additional Retype option will be provided to request confirmation.


Could be verified when ON_QA
Comment 5 Weihua Meng 2017-11-09 01:22:52 EST
Fixed.

openshift3/mediawiki-apb:v3.7.0-0.198.0.3
openshift3/mariadb-apb:v3.7.0-0.198.0.3
openshift3/mysql-apb:v3.7.0-0.198.0.3
openshift3/postgresql-apb:v3.7.0-0.198.0.3
Comment 8 errata-xmlrpc 2017-11-28 17:21:23 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2017:3188

Note You need to log in before you can comment on or make changes to this bug.