Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2008-06-15 09:49:22

uli
Moderator
From: Cologne
Registered: 2006-08-15
Posts: 4,306

Password in cleartext

A while ago I remarked there’s one password field to be filled in in cleartext in the process of installation. As far as I remember it’s the db pass.
[OT: There’s much activity with the new language files! Is 4.0.7 close ahead?]


In bad weather I never leave home without wet_plugout, smd_where_used and adi_form_links

Offline

#2 2008-06-15 14:53:07

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: Password in cleartext

The db password is stored only in config.php. It can’t be stored encrypted.

OT: no, not that close :)

Offline

#3 2008-06-15 14:57:44

uli
Moderator
From: Cologne
Registered: 2006-08-15
Posts: 4,306

Re: Password in cleartext

No, it’s not about storing, one input field is type=“text” instead of “password”


In bad weather I never leave home without wet_plugout, smd_where_used and adi_form_links

Offline

#4 2008-06-15 15:29:40

jm
Plugin Author
From: Missoula, MT
Registered: 2005-11-27
Posts: 1,746
Website

Re: Password in cleartext

The TXP user password uses the type=text value too.

Offline

#5 2008-06-15 16:31:40

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: Password in cleartext

The DB password is shown again in plain text in the bit of text that you have to copy/paste into the config.php file.
The TXP user password… hmmm.

Offline

#6 2008-06-17 14:04:32

Mary
Sock Enthusiast
Registered: 2004-06-27
Posts: 6,236

Re: Password in cleartext

It’s always been that way (as opposed to the user login form which has always been “hidden” as far as I can recall).

My guess is it was partly laziness: no “confirm” password field is then required, and that it was assumed if you were installing Txp you were in a “safe” location to begin with (no over-shoulder-lookers).

If it’s done away with, we should also have some jQuery goodness to instantly let you know if “password” and “password_confirm” match before you submit.

Last edited by Mary (2008-06-17 14:05:19)

Offline

Board footer

Powered by FluxBB