webadmin icon indicating copy to clipboard operation
webadmin copied to clipboard

Cleartext password in settings file!!!

Open rcfa opened this issue 1 year ago • 0 comments

If you go to …/settings/authentication/edit and set the Fallback Administrator admin’s password, it gets written out in plaintext into the config.toml

That’s a no go!

If one then logs in with the admin account and changes the password (even to the very same one), then it’s replaced with some hashed or encrypted version, as it should be.

Whatever mechanism is used when changing the password, should also be used when setting the password.

rcfa avatar Jan 07 '25 14:01 rcfa