2016-03-14, 20:38:22
(2016-03-14, 18:17:27)Bigin Wrote:(2016-03-14, 07:22:44)shawn_a Wrote: I think it is fine, it does not gain an attacker any priviledge escalation, viewing a page does not really constitute a high security scenario.
The same: that is no reason to store password in plain text.
The most people want to remember their password, so they use the same password everywhere at admin and front-end email etc. I do know people that accidentally deleted or have not uploaded important files like .htaccess, so that the xml files were accessible in a browser by DIRECT URL ACCESS like „www.website.com/data/pages/welcome_here_is_my_pass.html"
(2016-03-14, 07:22:44)shawn_a Wrote: Visible password is a feature also for sharing.
Yes, maybe in the old days (10 years ago), just like sending a new password in plaintext by email, on request
I said no.