Details
-
Type:
Improvement
-
Status:
Closed
-
Priority:
Minor
-
Resolution: Duplicate
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: scm
-
Labels:None
-
Number of attachments :
Description
The scm password is stored in plaintext in release.properties file. I think it would be safe not to save it there, then always prompt the user for the password every time.
Issue Links
- is depended upon by
-
CONTINUUM-2202
Do not show subversion password in plain text
-
- is related to
-
MRELEASE-648
Putting SVN password in settings.xml doesn't support password encryption
-
-
CONTINUUM-1741
release.properties file containing scm credentials in plain text is visible through the Web UI
-
- is superceded by
-
MRELEASE-420
Prepare and Perform should use profile server settings
-
- relates to
-
MRELEASE-341
support release process that use a staging repository
-
This can be a major issue in corporate environments with strict security rules.
In a single sign-on environment, exposing a password in plain text may compromise not only the source code repository, but all other systems the user has access to.