Skip to content

QT Desktop APP should not store password in plain text #1632

Description

@vilu85

if ($currentUser->authenticate($_POST['username'],$_POST['password']))

Desktop app (Qt) uses this for authentication. It would be better if checklogin.php would use hashed password for validation (hashed and then received by checklogin.php with POST) instead of plain text. This way the real password would never be stored as plain text on client side (Desktop app settings.xml).

Activity

  1. remdex commented on Mar 12, 2021

    @remdex
    Contributor

    I'll welcome pull request regarding that improvement :)
    Users also can choose do not store password also.
    Or they can use just electron version of the app.

  2. changed the title [-]Unsecure authentication[/-] [+]QT Desktop APP should not store password in plain text[/+] on Mar 16, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions