DASISH / dwan-backend

DASISH Task 5.6. Annotation framework backend
0 stars 1 forks source link

Insecure form for user registration #1

Open nostneji opened 10 years ago

nostneji commented 10 years ago

I noticed that web form for non-shibboleth user registration is not protected with SSL (http://lux17.mpi.nl/ds/webannotator/registerNonShibbolethPrincipal.html). Also the field for entering password is not masked. I understand that this is probably temporary solution, but I make this comment just in case 'temporary' turns out to be 'long time used'.

olhsha commented 10 years ago

Thanks. Anyway, authentication seems to be underspecified within the framework in general. I have just had a discussion with colleagues on another authentication related issue.

olhsha commented 10 years ago

Hiding password is fixed on loclahost. Adding SSL layer is postponed till next week to the discussion with Daan, Willem, Menzo.

olhsha commented 10 years ago

hiding passwords is deployed on lux 16