[mapguide-users] password fields is shown as being empty... when it isnt.

Jackie Ng jumpinjackie at gmail.com
Tue Sep 11 06:52:11 PDT 2012


This is a by-design decision made for security purposes in the latest Maestro
beta and stable releases.

Because if we can populate a password field in the UI, it means the password
has been stored plaintext in the Feature Source XML, which is *bad* because
under default security settings, users under the Anonymous MapGuide user
account can access this resource content.

When you open an existing Feature Source with properly secured credentials,
the password field is blank but the stored password is still the last saved
one and does not get overwritten until you enter a new value in the password
field and save the Feature Source.

I won't action any ticket to revert this behaviour. But I will take into
consideration any suggestions to improve the usability given these security
constraints.

- Jackie 



--
View this message in context: http://osgeo-org.1560.n6.nabble.com/password-fields-is-shown-as-being-empty-when-it-isnt-tp5001084p5001092.html
Sent from the MapGuide Users mailing list archive at Nabble.com.


More information about the mapguide-users mailing list