-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Description
When the results are successful, I would clean up the password and OTP fields.
To decide what to do if if fails (if it's easy to check if the error is only for the OTP, one could clean up that field only).
But maybe I would clean up everything (except username) also in that case?
I.e., as soon as you have some form of result I would clean those up.
This is for security, to avoid to keep a page with the password there (some browsers will allow to just click and show it).
And also because when I close the page, then my browser wants to save the password (and then this would be associated with the AiiDAlab domain...)
Metadata
Metadata
Assignees
Labels
No labels