Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use newer jelly tag for direct keys #59

Open
jetersen opened this issue Apr 26, 2019 · 7 comments
Open

Use newer jelly tag for direct keys #59

jetersen opened this issue Apr 26, 2019 · 7 comments

Comments

@jetersen
Copy link
Member

Use the new jelly tag secrettextarea
See for usage
jenkinsci/ssh-credentials-plugin#40

@stephenashank
Copy link
Contributor

@Casz Thanks for pointing this out. Is this a situation where it would be appropriate to blacklist the 0.8 release after releasing this fix?

@jetersen
Copy link
Member Author

jetersen commented Apr 26, 2019

it could be: see jenkins-infra/update-center2#263 for an example of this 😓

@stephenashank
Copy link
Contributor

Can you explain the utility/security that this provides over an invisible entry? We already don't render these keys, and it is still possible to view the encoded secret with secretTextarea through inspect element.

@stephenashank
Copy link
Contributor

The one use I could see would be directly inputting a secret without uploading a file

@jetersen
Copy link
Member Author

jetersen commented Apr 26, 2019

Ya, it is meant for direct key entries, sorry if that wasn't clear 👍

@jetersen
Copy link
Member Author

See screenshots at jenkinsci/jenkins#3967

@stephenashank
Copy link
Contributor

stephenashank commented Apr 26, 2019

Thanks for clarifying, I'm glad this is a feature request and not a security concern.

Support for direct input would be interesting, although I think it might require more thinking into how to integrate that with the existing file upload UI elements.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants