Re: Fwd: storing and using sensitive data

[email protected] (Ashley Sheridan)
Newsgroups php.general
Message-ID <[email protected]>
On 06/08/2021 16:42, Rene Veerman wrote:
> Rene Veerman 5864 <https://support.google.com/profile/120150990> 
> Original Poster
> 9 min
> eh, on windows 10, my username and password *are* filled in by autofill.
>
> but on my development machine, a kubuntu installation, it does not.
>
> i hope this is of help to google support..
> Rene Veerman 5864 <https://support.google.com/profile/120150990> 
> Original Poster
> 4 sec
> nvm! fixed by following the advice listed at 
> https://askubuntu.com/a/1185476 <https://askubuntu.com/a/1185476> :)
>
> ---------- Forwarded message ---------
> From: *Rene Veerman* <[email protected] 
> <mailto:[email protected]>>
> Date: Fri, Aug 6, 2021 at 1:05 PM
> Subject: Fwd: storing and using sensitive data
> To: PHP General <[email protected] 
> <mailto:[email protected]>>
>
>
> FYI :
> i've read 
> https://stackoverflow.com/questions/1354999/keep-me-logged-in-the-best-approach 
> <https://stackoverflow.com/questions/1354999/keep-me-logged-in-the-best-approach> 
> which explains a lot of the pitfalls involved,
> then i went searching for a library that does this for you, and found 
> https://github.com/gbirke/rememberme 
> <https://github.com/gbirke/rememberme> which appears to work great 
> right of the box.
>
> i'm now stuck at the autofill functionality.
> my site https://nicer.app <https://nicer.app>, with the login button 
> at the top-left of the pages, the middle icon on the right-side of the 
> date-time indicator,
> just won't autofill at all, other than offering a multitude of 
> previously used usernames, but i can't for the love of anything get it 
> to autofill the password field.
>
> this is the same for <input type="password" id="password" 
> name="password"> and <input type="password" id="current-password" 
> name="current-password">
>
> i could really use some help with that..
>
> ---------- Forwarded message ---------
> From: *Rene Veerman* <[email protected] 
> <mailto:[email protected]>>
> Date: Thu, Aug 5, 2021 at 6:30 PM
> Subject: storing and using sensitive data
> To: PHP General <[email protected] 
> <mailto:[email protected]>>
>
>
> Hi.
>
> I'm building a webmail module for my MIT-licensed 
> https://github.com/nicerapp/nicerapp 
> <https://github.com/nicerapp/nicerapp> websites platform (CMS and 
> more, see https://nicer.app <https://nicer.app> for a demo).
>
> I don't want to store end-user's email connection settings in plain 
> text on my server.
>
> I've read all of https://github.com/defuse/php-encryption 
> <https://github.com/defuse/php-encryption>, understand most of it, but 
> wonder if I can just encrypt the data using the end-user's password, 
> which gets verified by couchdb and as such is only stored as a hash 
> value in the database.
>
> Will my SSL connection setup, and the password stored in a cookie in 
> the end-user's browser, keep things safe enough to survive a 
> PHP/apache-based intrusion, which tends to open up every 2 years when 
> the guys at ubuntu.com <http://ubuntu.com> prepare for a new release..
>
> With regards,
>   Rene Veerman


Autofill tends to work based on the name and id of the field in 
question, and this behaviour varies quite a bit between browsers and 
operating systems. Have you looked at the `autocomplete` attribute 
(https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete) 
for that form element? In theory, you _should_ be able to set that to 
"current-password" to trigger the autocomplete behaviour. However, this 
is not a guarantee, it's just an attribute which suggests to the browser 
to do that, not an instruction that the browser must follow.

-- 
Ashley Sheridan
https://www.ashleysheridan.co.uk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.