Skip to content
GitHub
Sections

Reference · Things to avoid

Credential fields that fight the password manager

Forbidden
autocomplete="off" on a password, a paste handler that blocks pasting, a one-time-code field with no autocomplete
Instead
autocomplete="current-password", "new-password", "one-time-code", and nothing preventing paste.

What this rule looks like

Forbidden
Instead

Why this rule

Blocking the manager does not stop an attacker; it stops the reader using a long unique password, so they type a short one they can remember and reuse it everywhere. The interface decides which of those two happens.

Kind
Rule
Section
Things to avoid
Group
Safety at the interface
Bucket
mechanical
Severity
warning
Detector
interface-safety
Since
v0.14.0

Read as plain text