Esri / collector-tools

A set of python scripts and geoprocessing tools to automate common tasks and workflows in conjunction with Collector for ArcGIS
Apache License 2.0
74 stars 35 forks source link

Serious Security Issue #36

Closed tpcolson closed 6 years ago

tpcolson commented 6 years ago

Two of the tools call for an AGOL password, however, the password is displayed as plain text and stored in the GP history. This can be changed by setting the parameter to "String (hidden)", but should be default. In addition, this security issue isn't disclosed in the documentation for this tool, and instructions on how to obscure the password should be clearly communicated to tool users.

doug-m commented 6 years ago

Appreciate the feedback @tpcolson. We'll make this change shortly.

niti5425-zz commented 6 years ago

This issue has been addressed. Closing it.