[TYPO3-core] RFC #14307: fe_user passwords are visible in the info popup window in the backend

Philipp Gampe phil at philippgampe.info
Wed May 5 00:35:18 CEST 2010


Am 04.05.2010, 23:47 Uhr, schrieb Lars Houmark <lars at houmark.com>:

> How to test:
>
> - Create a Website user record
> - Click on the page module, then the page the user was created on
> - Click the user icon and click info
> - The popup shows the value of the password field
> - Apply the patch
> - The password is now changed to a random number of asterisk, reloading
> the popup window will show different length of asterisk
Thanks for the instructions.

+1 testing and reading on trunk

> Notes: I went through all core calls to the
> t3lib_befunc->getProcessedValue function and all of them is for display
> only, meaning change of the password to asterisk values cannot have any
> side effects.

I hope so. I did not made any further testing regarding that function.

Best regards
-- 
Philipp Gampe


More information about the TYPO3-team-core mailing list