[xwiki-devs] Getting sessions password
Tiago Rinck Caveden
caveden at gmail.com
Mon Jul 21 15:01:56 CEST 2008
By the way, recently I created my account on XWiki JIRA and it mailed me my
password in plain text, saying I could retrieve it at any moment again if I
wanted.
I didn't like that, it kind of showed me my password was being stored as
plain text...
Is this an issue of JIRA itself or some configuration of XWiki's JIRA? If
you can do anything to change it in your configuration, well, I don't know
if I can vote for such a thing, but here goes my +1. ;-)
If it's an issue of the JIRA platform and it can't be different, then maybe
putting some warnings as you do for the mailing list password? It would be
nice...
Best regards,
Tiago.
On Mon, Jul 21, 2008 at 2:51 PM, Vincent Massol <vincent at massol.net> wrote:
>
> On Jul 21, 2008, at 2:45 PM, MikSan wrote:
>
> >
> >
> > So there is now way i can retrive the password ?
>
> No. And that's a feature! :)
>
> What you can do is reset it though.
> See http://platform.xwiki.org/xwiki/bin/view/AdminGuide/User+Management
>
> -Vincent
>
> > Tiago Rinck Caveden wrote:
> >>
> >> On Mon, Jul 21, 2008 at 12:40 PM, MikSan <scan at netvisao.pt> wrote:
> >>
> >>>
> >>> How Do I get a session password?
> >>> I can get the username but not the password
> >>
> >>
> >>
> >> I don't believe you should ever be able to do it, passwords are
> >> supposed
> >> to
> >> be confidential.
> >> Allowing to retrieve them somehow already shows that the system
> >> stores the
> >> password as plain text instead of their hashes, what is a flaw IMHO.
> >>
> >> Best regards,
> >> --
> >> Tiago Rinck Caveden
> >> http://caveden.multiply.com
> _______________________________________________
> devs mailing list
> devs at xwiki.org
> http://lists.xwiki.org/mailman/listinfo/devs
>
--
Tiago Rinck Caveden
http://caveden.multiply.com
More information about the devs
mailing list