Actions
Task #80017
closedSecurity: Do not send password hashes when editing user records
Start date:
2017-02-25
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
8
PHP Version:
Tags:
Complexity:
Sprint Focus:
Description
Currently, when editing a user in the backend the password hash is sent as initial value for the (hidden) input field.
It is considered bad practice to expose password hashes to users.
Updated by Benni Mack over 7 years ago
- Target version changed from 8 LTS to Candidate for patchlevel
Updated by Oliver Hader almost 6 years ago
- Is duplicate of Task #59233: Do not transfer content of fields with eval=password added
Actions