-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Sharing with password -- Pressing enter to save password cannot be discovered #57
Comments
This may be related to oc-1949:
Can you confirm this? |
Thanks alot @LukasReschke this was indeed the issue. I think this is totally none discoverable. Submitting the password after every key stroke seems like a security issue, as an attacker could see how long it is by counting requests. Thanks for you quick help, would have never discovered that. |
This sounds resonable. @MTGap what do you think? |
Yes, submit on blur is good, and there needs to be some feedback like on the email field in the personal settings. (Or better yet, like the account settings fields here on Github with just a checkmark.) |
I changed it to set the new password as soon as the password filed loses focus. |
removing php-cloudfiles, replaced by php-opencloud
I tried to reproduce http://article.gmane.org/gmane.comp.kde.devel.owncloud/6035 to open a bug for it.
However, I came to realize that it does not work at all. Setting the expiration date or enabling sharing is saved without an issue.
However, if i open the share menu and enter a password (press the lock icon) this is not saved. Looking at Firebug, nothing is transfered to the server doing so.
However there is no error message and thus I by accident shared without any password at all.
This is FF16 and ownCloud git.
The text was updated successfully, but these errors were encountered: