fix(auth): prevent browser autofill of PAT field#693
Conversation
…ecurity guard The Personal Access Token input field did not set autocomplete='new-password'. Browsers with saved form data could auto-fill the field with stored passwords or prefill it on page load, potentially exposing the credential without the user's intent. Set inputProps.autoComplete to 'new-password' on the PAT TextField so browsers treat the field as a new-credential input rather than a fillable login field. The field already uses type='password' for masking; this change prevents the autofill vector. Closes GitMetricsLab#687
✅ Deploy Preview for github-spy ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Warning Review limit reached
More reviews will be available in 57 minutes and 2 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description
The Personal Access Token input field did not set an autocomplete attribute. Browsers with saved form data could auto-fill the field with previously stored passwords, potentially placing a credential into the PAT field without the user's intent and without them knowing which credential was filled.
Root Cause
The TextField for the PAT did not specify inputProps.autoComplete. Browsers default to treating password fields as login credentials and may autofill them from the password manager.
Related Issue
Closes #687
Type of Change
Changes Made
Testing Done
Checklist