bwsw / cloudstack-ui

Modern UI for Apache Cloudstack User Self Service Portal
https://bitworks.software/
Apache License 2.0
164 stars 63 forks source link

Pass user's login, password and domain in GET request #1603

Closed elenaustyugova closed 4 years ago

elenaustyugova commented 5 years ago

Description

There should be a functionality of transmitting user's login, password and domain via URL and hide them immediately after auth.

This issue covers the following requirements:

REQ_LOGIN_003

andrewbents commented 4 years ago

A browser history entry is created with user's login and password. This can be worked around and is a possible security issue. Thus closing the issue