You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Both firefox and chrome can autofill some username and password fields in forms without user interaction. This is a problem specially in the users page where the password field is hidden but the browser autocompletes it.
Note that neither safari nor edge have this behaviour. They require user interaction in order to fill the password field. This problem doesn't happen in those browsers.
Related Issue
no ticket opened as far as I know.
Motivation and Context
The admin was setting a password without any knowledge.
How Has This Been Tested?
Checked with firefox, chrome, safari and edge:
login as admin.
when prompted, save the password in the browser
go to the users page
at this point the new username and password fields should be empty (this needs to be even if the password field isn't visible)
add a new user using the username + email fields
in a new browser, check the email sent and reset the password for that user
note that the password field for the reset form are also empty.
Screenshots (if appropriate):
Types of changes
Bug fix (non-breaking change which fixes an issue)
New feature (non-breaking change which adds functionality)
Database schema changes (next release will require increase of minor version instead of patch)
Breaking change (fix or feature that would cause existing functionality to change)
Technical debt
Tests only (no source changes)
Checklist:
Code changes
Unit tests added
Acceptance tests added
Documentation ticket raised:
Open tasks:
Backport (if applicable set "backport-request" label and remove when the backport was done)
jvillafanez
changed the title
[stable10] Tell the browser not to autofill those password fields
Tell the browser not to autofill those password fields
Aug 5, 2019
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
You can’t perform that action at this time.
✕
Wait! Don't Go Yet 🚀
Get our FREE eBook "10 Programming Tips That Changed Everything" when you subscribe!
Description
Both firefox and chrome can autofill some username and password fields in forms without user interaction. This is a problem specially in the users page where the password field is hidden but the browser autocompletes it.
Note that neither safari nor edge have this behaviour. They require user interaction in order to fill the password field. This problem doesn't happen in those browsers.
Related Issue
no ticket opened as far as I know.
Motivation and Context
The admin was setting a password without any knowledge.
How Has This Been Tested?
Checked with firefox, chrome, safari and edge:
Screenshots (if appropriate):
Types of changes
Checklist:
Open tasks:
This should be moved to the user_management app