o365-moodle icon indicating copy to clipboard operation
o365-moodle copied to clipboard

authentication secret is visible in plain text

Open mjonila opened this issue 8 months ago • 0 comments

When setting up SSO for Moodle, I found that Client Secret is being saved and displayed as plain text without any restriction. Could you please change the plugin to hide it after saving initial setup ? Otherwise any Moodle admin can get into Plugin page and copy Client secret and Application id and essentially have working credentials to login to Microsoft 365 tenant:

Image

mjonila avatar Apr 02 '25 15:04 mjonila