A user is able to paste password from any normal text-field to the password field in all forms PublicLab uses for user authentication. This should be resolved since user should not be able to paste the password in the password field.

@kunalvaswani123 please continue to work on other similar pages. We will resolve the travis error soon and merge things all at once.
yeah I'll create a pr for edit form and ftos for rest
There are many ftos right now. We generally favour ftos but there are many PRs of login/signup by many people. So if you create an fto then there will be many conflicts as 5-6 prs of OAuth milestone will be merged by the time any fto candidate takes on this issue. So it will be better if you will send us prs yourself.
Thanks
Sorry to jump in here randomly, but as someone who uses a password manager (specifically, LastPass) this feature is very inconvenient. Any chance this issue could be opened up for discussion again and possibly reverted? I believe a fair number of people use password managers
Hi @tahnok, for sure, we can't deny this fact that many people use password managers, so let's ask @publiclab/community-reps @publiclab/plots2-reviewers about their views. Thanks!
@jywarren
Agreed, I think that's a good justification to keep this field paste-able!
On Mon, Jan 6, 2020 at 9:13 PM Sidharth Bansal notifications@github.com
wrote:
@jywarren https://github.com/jywarren
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
https://github.com/publiclab/plots2/issues/4487?email_source=notifications&email_token=AAAF6J5C6YLLZHK2WRHADTTQ4PQNTA5CNFSM4GMXMHE2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOEIHOHGI#issuecomment-571401113,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/AAAF6J4VWCW265XXR643RXLQ4PQNTANCNFSM4GMXMHEQ
.
Thanks
Most helpful comment
Sorry to jump in here randomly, but as someone who uses a password manager (specifically, LastPass) this feature is very inconvenient. Any chance this issue could be opened up for discussion again and possibly reverted? I believe a fair number of people use password managers