jira.codehaus.org

  • Log In Access more options
    • Online Help
    • Keyboard Shortcuts
    • About JIRA
    • JIRA Credits
    • What?s New
  • Dashboards Access more options (Alt+d)
  • Projects Access more options (Alt+p)
  • Issues Access more options (Alt+i)
  • Maven Wagon
  • WAGON-52

wagon-webdav does not ask for auth password when <username>...</username> is missing

  • Log In
  • Views
    • XML
    • Word
    • Printable

Details

  • Type: Improvement Improvement
  • Status: Closed Closed
  • Priority: Major Major
  • Resolution: Won't Fix
  • Affects Version/s: 1.0-beta-1
  • Fix Version/s: None
  • Component/s: wagon-webdav
  • Labels:
    None
  • Environment:
    Linux and Windows

Description

We use as internal repository a WebDav server with BASIC authentication. Only internal developers have access to this WebDav server and so e.g. internship students do not have access to company jars.

Now when the server definition in settings.xml does not contain the <username>...</username> element, then wagon-webdav should ask once for the missing password on the command line. Right now it just fails.

Issue Links

is related to

Improvement - An improvement or enhancement to an existing feature or task. MDEPLOY-51 Prompt for username and password if not supplied

  • Major - Major loss of function.
  • Open - The issue is open and ready for the assignee to start work on it.
relates to

New Feature - A new feature of the product, which has yet to be developed. MNG-553 Secure Storage of Server Passwords

  • Critical - Crashes, loss of data, severe memory leak.
  • Closed - The issue is considered finished, the resolution is correct. Issues which are not closed can be reopened.

Activity

Ascending order - Click to sort in descending order
  • All
  • Comments
  • Work Log
  • History
  • Activity
Hide
Permalink
Carlos Sanchez added a comment - 22/Jun/06 10:50 AM

None of the wagons do that. In any case requires a change in the way it works

Show
Carlos Sanchez added a comment - 22/Jun/06 10:50 AM None of the wagons do that. In any case requires a change in the way it works
Hide
Permalink
Joe Cool added a comment - 23/Jun/06 4:30 AM

Hmm IMHO this is a serious security issue. I do not want to store my password unencrypted in a text file.

Show
Joe Cool added a comment - 23/Jun/06 4:30 AM Hmm IMHO this is a serious security issue. I do not want to store my password unencrypted in a text file.
Hide
Permalink
Carlos Sanchez added a comment - 23/Jun/06 6:14 AM

Then that's a different issue, see MNG-553

Show
Carlos Sanchez added a comment - 23/Jun/06 6:14 AM Then that's a different issue, see MNG-553
Hide
Permalink
galmeida added a comment - 04/Jun/07 11:01 AM

Even storing encrypted password is considered insecure by some organizations/individuals, wagons should really ask for passwords when they can not be found in settings.xml (or other more secure store)

Show
galmeida added a comment - 04/Jun/07 11:01 AM Even storing encrypted password is considered insecure by some organizations/individuals, wagons should really ask for passwords when they can not be found in settings.xml (or other more secure store)
Hide
Permalink
Brett Porter added a comment - 27/May/08 6:33 AM

this needs to be addressed in Maven, not in Wagon

Show
Brett Porter added a comment - 27/May/08 6:33 AM this needs to be addressed in Maven, not in Wagon
Hide
Permalink
Joe Cool added a comment - 27/May/08 7:04 AM

@Brett: did you open an issue/event for Maven regarding this problem? If yes please add the URL here; if no please start such an vent.

Regards && thanks!

Show
Joe Cool added a comment - 27/May/08 7:04 AM @Brett: did you open an issue/event for Maven regarding this problem? If yes please add the URL here; if no please start such an vent. Regards && thanks!
Hide
Permalink
Brett Porter added a comment - 27/May/08 7:14 AM

MNG-553 covers the alternative of prompting for passwords

Show
Brett Porter added a comment - 27/May/08 7:14 AM MNG-553 covers the alternative of prompting for passwords

People

  • Assignee:
    Brett Porter
    Reporter:
    Joe Cool
Vote (3)
Watch (1)

Dates

  • Created:
    22/Jun/06 10:38 AM
    Updated:
    27/May/08 7:14 AM
    Resolved:
    27/May/08 6:33 AM
  • Atlassian JIRA (v5.0.4#731-sha1:3aa7374)
  • Report a problem
  • Powered by a free Atlassian JIRA open source license for Codehaus. Try JIRA - bug tracking software for your team.