Security-Tools-Alliance / rengine-ng

reNgine-ng is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface.
GNU General Public License v3.0
12 stars 6 forks source link

Mask api keys in settings #67

Closed 0b3ud closed 1 month ago

0b3ud commented 2 months ago

I was able to add a button to hide API Key, responding to issue #57

I was able to do so by refactoring / reusing HTML code from the loggin page,
and It works as following :

I have integrated this feature in API Vault and HackerOne Views in Settings as shown in the screenshots bellow :

API Vault :

image

Hackerone :

image

Please keep in mind that I am not a hunter and I don't use RENGINE on daily bases, testing this feature would be appreciated

Thanks in advance 🥇

Talanor commented 1 month ago

Value in HTML will leak the password. I have a working version with empty field