← Back to team overview

mahara-contributors team mailing list archive

[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials

 

The scope of this is a bit larger than the LDAP credentials, given the
potential variety in accessible domains.

One could potentially use key-based encryption, storing the key in
config.php, using mcrypt.  It wouldn't be bulletproof, but it would
prevent against SQL injection attacks or misplaced database dumps.

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/1016253

Title:
  Authenticated RSS feeds should encrypt login credentials

Status in Mahara ePortfolio:
  New

Bug description:
  The externalfeed block should protect user credentials when
  authenticated RSS feeds are used.  The blocktype in Mahara 1.5.1
  appears to store login credentials in cleartext within the database.

  This presents an unfortunate vulnerability that could give access to
  other systems should Mahara's database be compromised.

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1016253/+subscriptions


References