Autogenerated password in history
-
The autogenerated password during the restore process is passed to the form where you can set a new one as a get parameter. Therefor it is stored in the browser’s history.
Can I suggest to generate the password only when outputting the form code instead of passing it along in a redirect?
As it is a site may secure transmission of sensitive data by using SSL which is underminded by sending it in the clear as part of a request.
Viewing 7 replies - 1 through 7 (of 7 total)
Viewing 7 replies - 1 through 7 (of 7 total)
- The topic ‘Autogenerated password in history’ is closed to new replies.