Skip to content

Smtp creds are visible to end user - Security Risk #1524

@ckieler-cb

Description

@ckieler-cb

Hello,

If we set LockSettings = true

The window for the settings shows and if the user has provided smtp credentials (under message relay tab) they can open dev tools and remove the type="password" to expose the smtp password.

image

image

In previous versions of this tool, the ability to open the window was disabled altogether via LockSettings = true.

Could the frontend be updated to not include the actual values when LockSettings = true ?

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions