passbolt / passbolt_api

Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
https://passbolt.com
GNU Affero General Public License v3.0
4.63k stars 305 forks source link

Password can be read after logout #422

Closed Geisterli closed 2 months ago

Geisterli commented 2 years ago

Password can be read after logout

What you did

What you expected to happen

I expect no passwords to be displayed after the automatic logout.

AnatomicJC commented 2 years ago

Hi @ChristianKippingKv-rlp and thanks for reporting this issue 👍

We created an internal ticket under reference PB-14173 to handle this. We will keep you posted as soon as the fix will be published.

With best regards,

TreasureCove commented 6 months ago

You'll also encrypt or drop it after that ticker right? not just change the ui? not that one can change in memory stuff and it'll get visibel or just read out :P

cedricalfonsi commented 2 months ago

Fixed with v4.9.0.