You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello,
storing the password in the connection object enables me to spy easily the passwords of my users when they login. The password should be immediately thrown away once connected and not stored. It looks like its anyhow not used, so why store it?
This package is used by a login screen in my app and I can now easily see the passwords of my users.
The application will not pass a security scan of our cybersecurity team.
The text was updated successfully, but these errors were encountered:
Hi guys,
is this issue not important? I can extract and store the password of my users after they have logged in using ldap3 authentication. Why in the world is it necessary to store the password?
Hello,
storing the password in the connection object enables me to spy easily the passwords of my users when they login. The password should be immediately thrown away once connected and not stored. It looks like its anyhow not used, so why store it?
This package is used by a login screen in my app and I can now easily see the passwords of my users.
The application will not pass a security scan of our cybersecurity team.
The text was updated successfully, but these errors were encountered: