Not show value of $g_smtp_password in custom_config.inc.php

Ask community to help.

Moderators: Amaradana, TurboPT, TL Developers

Not show value of $g_smtp_password in custom_config.inc.php

Postby segicas2015 » Wed Dec 30, 2015 8:18 pm

In the file custom_config.inc.php, we can set the value of the field $g_smtp_password and that password can be viewed by anyone who has access to the file:

For example:

$g_smtp_username = 'myUser'; # user
$g_smtp_password = 'myPassword'; # password

My question is if is it possible to not show the value of the field $g_smtp_password ? How?

Thank you.
segicas2015
TestLink user
 
Posts: 5
Joined: Sun Nov 01, 2015 11:19 am

Re: Not show value of $g_smtp_password in custom_config.inc.

Postby fman » Thu Dec 31, 2015 4:17 pm

same happens with password for db access in config_db.inc.php
The password has always been in plain text.
If you have the correct permissions on it, the file is only readable for the right group of users.
fman
Member of TestLink Community
 
Posts: 3063
Joined: Tue Nov 15, 2005 7:19 am

Re: Not show value of $g_smtp_password in custom_config.inc.

Postby segicas2015 » Tue Jan 05, 2016 7:47 pm

Yes, but I am not the only one that has access into that folder and then I wanted to hide or mask that password because it is the password of my e-mail.

What do you recommend to me regarding that?
segicas2015
TestLink user
 
Posts: 5
Joined: Sun Nov 01, 2015 11:19 am

Re: Not show value of $g_smtp_password in custom_config.inc.

Postby fman » Thu Jan 07, 2016 5:06 pm

No way
But is absolutely wrong using your user to connect to smtp server, you need to create a SERVICE ACCOUNT.
You need to protect the folder using good rights at file system level
fman
Member of TestLink Community
 
Posts: 3063
Joined: Tue Nov 15, 2005 7:19 am


Return to Installation and configuration



Who is online

Users browsing this forum: No registered users and 4 guests