Credential fields that fight the password manager
- Forbidden
autocomplete="off"on a password, apastehandler that blocks pasting, a one-time-code field with noautocomplete- Instead
autocomplete="current-password","new-password","one-time-code", and nothing preventing paste.
What this rule looks like
Why this rule
Blocking the manager does not stop an attacker; it stops the reader using a long unique password, so they type a short one they can remember and reuse it everywhere. The interface decides which of those two happens.
- Kind
- Rule
- Section
- Things to avoid
- Group
- Safety at the interface
- Bucket
- mechanical
- Severity
- warning
- Detector
interface-safety- Since
- v0.14.0