Closed

Description
- Gitea version (or commit ref): 1.8.3
- Git version: 1.8.3.1
- Operating system: Red Hat Enterprise Linux 7.6
- Database (use
[x]
):- PostgreSQL
- MySQL
- MSSQL
- SQLite
- Can you reproduce the bug at https://try.gitea.io:
- Yes (provide example URL)
- No
- Not relevant
- Log gist:
Description
When creating a mirror of a downstream git repo, https mirroring is the only option, and when using an authenticated mirror you must supply credentials for the mirror. These credentials then become part of the properties in the administration section of the mirror, and the password is displayed in plain clear text. This was confirmed on https://try.gitea.io and I have provided a screenshot that shows this security issue that exposes secrets in plain clear text with no option to mask the secret.
- Test repo: https://try.gitea.io/testyuser/demo
- Mirror repo: https://try.gitea.io/testyuser/demo-mirror
- Username: testyuser
- Password: password