Skip to content

Security: Bitbucket OAuth Client Secret is displayed as plain text #27

@jfrerich

Description

@jfrerich

From GH comment: #5 (review)

5) The Bitbucket OAuth Client Secret is displayed as plain text in the System Console. When the config is saved and page is reloaded, this should not be exposed. We should mask it.

Severity: Low

Steps:

  • Login as a sysadmin user and install the bitbucket plugin.
  • Visit the bitbucket configuration page and enter Oauth client ID and secret and save.
  • Reload the page and notice that the secret is still displayed in plain text.
  • Like other config pages, i.e say OAuth config page on System console, the secret key should be
    truncated and displayed as ******. It should not be returned as plain text in config API

Metadata

Metadata

Assignees

No one assigned

    Labels

    Help WantedCommunity help wantedNeeds Mattermost ChangesRequires changes to the Mattermost Plugin tookitType/EnhancementNew feature or improvement of existing featureUp For GrabsReady for help from the community. Removed when someone volunteers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions