Bug 173314 - HTTP Proxy password shown in clear text
Summary: HTTP Proxy password shown in clear text
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Server
Version: 400
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Mike McCune
QA Contact: Vlady Zlatkin
URL:
Whiteboard:
: 144384 (view as bug list)
Depends On:
Blocks: 178198 203352
TreeView+ depends on / blocked
 
Reported: 2005-11-16 09:25 UTC by Matthew Booth
Modified: 2007-07-31 15:29 UTC (History)
3 users (show)

Fixed In Version: rhn406
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-03-15 19:44:02 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Matthew Booth 2005-11-16 09:25:40 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-GB; rv:1.7.12) Gecko/20050921 Red Hat/1.0.7-1.4.1 Firefox/1.0.7

Description of problem:
Go to Satellite Tools -> Satellite Configuration. The "HTTP proxy password" is shown in clear text. As this is a password it should use <input type="password">. There should probably also be 2 of them.

Version-Release number of selected component (if applicable):
rhn401

How reproducible:
Always

Steps to Reproduce:
1. Go to Satellite Tools -> Satellite Configuration

Actual Results:  Joe User standing near administrator views proxy details and goes on pr0n downloading spree safe in the knowledge that he's not using his own login details.  Sexual harassment lawsuits against all our large corporate customers, and the moral collapse of society.

Expected Results:  ********

Additional info:

Comment 1 Matthew Booth 2005-11-16 09:44:16 UTC
Also, it would be useful to be able to leave authentication details blank.
satellite-sync should prompt for them interactively if required.

Comment 4 Mike McCune 2006-01-26 16:50:14 UTC
*** Bug 144384 has been marked as a duplicate of this bug. ***

Comment 6 Mike McCune 2006-02-06 20:10:57 UTC
TESTPLAN:

1) Nav to Satellite Tools -> Satellite Configuration
2) verify that the HTTP Proxy Password field shows ***** when you  type
   in a password.
3) submit form.  verify that it still shows *****


Comment 7 Vlady Zlatkin 2006-02-15 23:38:32 UTC
works

Comment 8 Vlady Zlatkin 2006-03-03 23:10:31 UTC
verified in stage, and verified content of satellite to match previously blessed
content

Comment 9 Todd Warner 2006-03-15 19:44:02 UTC
Closing upon release of RHN 406


Note You need to log in before you can comment on or make changes to this bug.