[Bug] Active Directory Admin Bind Credentials exposed #8012
Replies: 1 comment
-
|
Yeah, that's not ideal. The admin bind password should definitely be masked in the UI. This looks like a bug in the wiki.js administration panel — the password field for the LDAP/AD strategy is being rendered as a regular text input instead of a password input. If you're concerned about exposure in the meantime, the password is stored in the database (in the You should probably report this as a bug on the wiki.js GitHub issues rather than here in discussions — it's a straightforward UI fix (changing the input type to |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Would prefer/expect the Admin Bind Credentials, which is the password for the service account we are using to authenticate to AD, would be ****'d out.
Thanks
-Harv
Beta Was this translation helpful? Give feedback.
All reactions