Project

General

Profile

Bug #5623

Credentials for remote repository URL leaking in Repository Header

Added by Fletcher Johnston 11 months ago. Updated 10 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
16.06.2020
Due date:
% Done:

0%

Estimated time:
Sorting:
Commit Number:
Affected Version:

Description

Credentials for remote repertoires are asterisked out in the Remote pull uri field under Repository Settings > Remote Sync. Nice!
However, they are displayed in plain text below the Repository heading, to all users, regardless of role. Please see attached screenshot.

I'm currently running RhodeCode EE 4.19.1.

I would request that they be obfuscated here as well, and would suggest that the clone URL does not need to be a link. Or, could just be a link to the root repository URL, without the credentials.


Files

Credentials.jpg (91.7 KB) Credentials.jpg Fletcher Johnston, 16.06.2020 21:10
rhodecode version.jpg (13.7 KB) rhodecode version.jpg Fletcher Johnston, 22.06.2020 13:30
repo credentials.jpg (76.7 KB) repo credentials.jpg Fletcher Johnston, 22.06.2020 13:33

Also available in: Atom PDF