Explorar o código

Merge pull request #5702 from weseek/fix/block-password-autocomplete-in-me-page

fix: Prevent auto completing email with username stored by browser in /me page
Yuki Takei %!s(int64=4) %!d(string=hai) anos
pai
achega
2b25b8b6a9
Modificáronse 1 ficheiros con 3 adicións e 0 borrados
  1. 3 0
      packages/app/src/components/Me/PasswordSettings.jsx

+ 3 - 0
packages/app/src/components/Me/PasswordSettings.jsx

@@ -99,6 +99,9 @@ class PasswordSettings extends React.Component {
           <div className="row mb-3">
             <label htmlFor="oldPassword" className="col-md-3 text-md-right">{ t('personal_settings.current_password') }</label>
             <div className="col-md-5">
+              {/* to prevent autocomplete username into userForm[email] in BasicInfoSettings component */}
+              {/* https://developer.mozilla.org/en-US/docs/Web/Security/Securing_your_site/Turning_off_form_autocompletion */}
+              <input type="password" autoComplete="new-password" style={{ display: 'none' }} />
               <input
                 className="form-control"
                 type="password"