in reply to Re: Re: User Editor Page and clear text passwords
in thread User Editor Page and clear text passwords

At least not pre-filling the password box is a simple step. How hard IS that? I mean that most literally, not sarcastically. What's the work that is involved beyond checking if the password fields are not nil and match?

How easy would it be to put a disclaimer near the password box?


Play that funky music white boy..
  • Comment on Re: Re: Re: User Editor Page and clear text passwords

Replies are listed 'Best First'.
Re: Re: Re: Re: User Editor Page and clear text passwords
by demerphq (Chancellor) on Feb 15, 2004 at 23:03 UTC

    Ah, the way I see it is that these things are handled automatically. So what you are talking about is providing special case behaviour for a single field in the user object. Its possible sure, but its not straight forward. Its definately not a whip out a patch in 30 minutes (or 2 minutes for that matter) that it might be in some scenarios. Yes, I personally as a pmdever will look into it, no I did not see a clean and obvious patch to do it when I first looked after reading your node.


    ---
    demerphq

      First they ignore you, then they laugh at you, then they fight you, then you win.
      -- Gandhi


      I know this reply will get voted down, but please do. Even if at worst, a warning on the user page on that the state of security is neither ideal nor dire, but you shouldn't use a common password as the page does contain the password to begin with. :(

      Play that funky music white boy..