vaadin/framework
PasswordField should not contain real password
Ouverte
#10 544 ouverte le 17 janv. 2018
Good First IssueHelp wantedenhancement
Métriques du dépôt
- Stars
- (1 806 étoiles)
- Métriques de merge PR
- (Métriques PR en attente)
Description
This behavior is working as described in the documentation:
Unless the server connection is encrypted with a secure connection, such as HTTPS, the input is transmitted in clear text and may be intercepted by anyone with low-level access to the network.
I think it would be good practice to not reveal the actual password to the browser. The PasswordField should handle this transparently.
This was observed with Vaadin 8.2.1, but since it is working as documented, every version will be affected.