Comment 3 for bug 528450

Revision history for this message
Matt Giuca (mgiuca) wrote :

This is a bit of a security risk (for the same reason we typically show ***s in password fields). We don't want someone happening to look over someone else's shoulder and getting their SVN password.

Only show it on the user page (the lecturer submissions page should have a link to that page). And make it display: hidden with a Javascript clicky top open it up.

Thoughts? I'm still concerned that it lets someone who randomly accesses someone's account to get the svn password. For even better security, we should potentially have a separate form where we ask them to enter their IVLE password before displaying the svn password.