wernerjoss / wp-caldav2ics

Development Repo for https://wordpress.org/plugins/wp-caldav2ics/
GNU General Public License v2.0
5 stars 4 forks source link

Passwords stored in plain text #4

Open leoniscsem opened 2 years ago

leoniscsem commented 2 years ago

When saving the configuration, the passwords for accessing the CalDav interface are not obfuscated. In a multi-user setup with several admins managing the site, thus the plugin reveals Nextcloud full-access credentials to everyone.

Ansonsten tolles Plugin!

wernerjoss commented 2 years ago

hi @leoniscsem , it's been a long time now I looked into this repo last time, so I missed your issue, sorry. and, yes, you are right with your comment - showing the credentials to all admins might be a security issue. however, I have stopped WP Plugin development long ago, so it is (currently) unlikely, I will do any further improvements here. but who knows - maybe I'll be back in the future, or anyone is willing to pick this up and create a patch/pull request. so, I'll just leave this open ATM.