Ticket #65 (closed defect: wontfix)

Opened 6 years ago

Last modified 6 years ago

Password for VoIP is displayed

Reported by: bochecha Owned by: somebody
Priority: major Milestone:
Component: Web UI Version:
Keywords: Cc:
Blocked By: Blocking:

Description

In the VoIP section, the password is displayed, both in the input field and in the informations summary.

Rather disturbing, the password input field is:

<input size="8" id="asterisk_pass" name="asterisk_pass" value="" type="text">

when it should be:

<input size="8" id="asterisk_pass" name="asterisk_pass" value="" type="password">

Displaying the password gives a weird impression of insecurity, even if the communication is encrypted using HTTPS (someone might be behind my back when I enter my password / view my VoIP informations).

Change History

comment:1 Changed 6 years ago by ynemoy

  • Status changed from new to closed
  • Resolution set to wontfix

(17.05.55) (@mmcgrath) loupgaroublond: take this scenario into account (17.05.59) (@mmcgrath) 1) user has a meeting to attend to. (17.06.05) (@mmcgrath) 2) user tries to log in at meeting time. (17.06.09) (@mmcgrath) 3) user forgot password (17.06.13) (@mmcgrath) 4) user changes password (17.06.20) (@mmcgrath) 5) user misses meeting because the password sync isn't immediate.

In short, NOTABUG.

We could argue for a feature to let the user decide this, but then we have two equally competing arguments of whether it should be hidden or not by default. It's not a matter of dumbing the interface down for a certain scenario or limiting a choice here, because offering the choice could have some very dire circumstances.

Note: See TracTickets for help on using tickets.