Password Preview

Václav Suchánek, modified 1 Year ago. Junior Member Posts: 26 Join Date: 8/15/18 Recent Posts

During login or password change, the user should have the option to temporarily view the entered password.

The goal of this requirement is for the user to be able to verify their input and successfully enter the memorized secret.

The verifying party should offer the option to display the secret — instead of a series of dots or asterisks — until it is entered. The verifying party may also allow the user's device to display individual entered characters for a short time after each character is typed to verify the correct entry, especially on mobile devices.

See ASVS v4.0.3, section 2.1.12:
Verify that the user can choose to either temporarily view the entire masked password, or temporarily view the last typed character of the password on platforms that do not have this as built-in functionality.

thumbnail
Václav Suchánek, modified 1 Year ago. Liferay Master Posts: 764 Join Date: 1/5/10 Recent Posts

Hi Václav,

We already have a feature request for this: https://liferay.atlassian.net/browse/LPS-189345. We're going to work on that.

Thanks,
Zsigmond

Václav Suchánek, modified 1 Year ago. Junior Member Posts: 26 Join Date: 8/15/18 Recent Posts

Thank you, Zsigmond.