From b8b96b7af8d7146eafb1d4e59560ec087cfe8ae1 Mon Sep 17 00:00:00 2001 From: Nate Date: Fri, 12 Apr 2019 10:18:03 -0600 Subject: [PATCH] Additional browser autofill prevention for Devices, Fax, Gateway and User --- app/devices/device_edit.php | 2 ++ app/fax/fax_edit.php | 6 ++++-- app/gateways/gateway_edit.php | 21 +++------------------ core/users/user_edit.php | 4 ++-- 4 files changed, 11 insertions(+), 22 deletions(-) diff --git a/app/devices/device_edit.php b/app/devices/device_edit.php index fd3649c51a..4dd1c54784 100644 --- a/app/devices/device_edit.php +++ b/app/devices/device_edit.php @@ -1008,11 +1008,13 @@ if (permission_exists('device_line_auth_id')) { echo " \n"; echo " \n"; + echo " \n"; //help defeat browser auto-fill echo " \n"; } if (permission_exists('device_line_password')) { echo " \n"; + echo " "; //help defeat browser auto-fill echo " \n"; echo " \n"; } diff --git a/app/fax/fax_edit.php b/app/fax/fax_edit.php index 5c440e1dd9..0d5b6a73f7 100644 --- a/app/fax/fax_edit.php +++ b/app/fax/fax_edit.php @@ -634,7 +634,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " ".$text['label-user-list'].""; echo " "; - $sql = "SELECT * FROM v_fax_users as e, v_users as u "; + $sql = "select * from v_fax_users as e, v_users as u "; $sql .= "where e.user_uuid = u.user_uuid "; $sql .= "and e.domain_uuid = '".$_SESSION['domain_uuid']."' "; $sql .= "and e.fax_uuid = '".$fax_uuid."' "; @@ -656,7 +656,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " \n"; echo "
\n"; } - $sql = "SELECT * FROM v_users "; + $sql = "select * from v_users "; $sql .= "where domain_uuid = '".$_SESSION['domain_uuid']."' "; if (isset($assigned_user_id)) foreach($assigned_user_uuids as $assigned_user_uuid) { $sql .= "and user_uuid <> '".$assigned_user_uuid."' "; @@ -920,6 +920,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo "\n"; echo "\n"; echo " \n"; + echo " \n"; //help defeat browser auto-fill echo "
\n"; echo " ".$text['description-email_connection_username']."\n"; echo "\n"; @@ -930,6 +931,7 @@ if (count($_POST)>0 && strlen($_POST["persistformvar"]) == 0) { echo " ".$text['label-email_connection_password']."\n"; echo "\n"; echo "\n"; + echo " \n"; //help defeat browser auto-fill echo " \n"; echo "
\n"; echo " ".$text['description-email_connection_password']."\n"; diff --git a/app/gateways/gateway_edit.php b/app/gateways/gateway_edit.php index 1888191b9a..d1e37b58b8 100644 --- a/app/gateways/gateway_edit.php +++ b/app/gateways/gateway_edit.php @@ -124,39 +124,22 @@ //check for all required data $msg = ''; - //if (strlen($domain_uuid) == 0) { $msg .= $text['message-required']." ".$text['label-domain_uuid']."
\n"; } if (strlen($gateway) == 0) { $msg .= $text['message-required']." ".$text['label-gateway']."
\n"; } if ($register == "true") { if (strlen($username) == 0) { $msg .= $text['message-required']." ".$text['label-username']."
\n"; } if (strlen($password) == 0) { $msg .= $text['message-required']." ".$text['label-password']."
\n"; } } - //if (strlen($distinct_to) == 0) { $msg .= $text['message-required']." ".$text['label-distinct_to']."
\n"; } - //if (strlen($auth_username) == 0) { $msg .= $text['message-required']." ".$text['label-auth_username']."
\n"; } - //if (strlen($realm) == 0) { $msg .= $text['message-required']." ".$text['label-realm']."
\n"; } - //if (strlen($from_user) == 0) { $msg .= $text['message-required']." ".$text['label-from_user']."
\n"; } - //if (strlen($from_domain) == 0) { $msg .= $text['message-required']." ".$text['label-from_domain']."
\n"; } if (strlen($proxy) == 0) { $msg .= $text['message-required']." ".$text['label-proxy']."
\n"; } - //if (strlen($register_proxy) == 0) { $msg .= $text['message-required']." ".$text['label-register_proxy']."
\n"; } - //if (strlen($outbound_proxy) == 0) { $msg .= $text['message-required']." ".$text['label-outbound_proxy']."
\n"; } if (strlen($expire_seconds) == 0) { $msg .= $text['message-required']." ".$text['label-expire_seconds']."
\n"; } if (strlen($register) == 0) { $msg .= $text['message-required']." ".$text['label-register']."
\n"; } - //if (strlen($register_transport) == 0) { $msg .= $text['message-required']." ".$text['label-register_transport']."
\n"; } if (strlen($retry_seconds) == 0) { $msg .= $text['message-required']." ".$text['label-retry_seconds']."
\n"; } - //if (strlen($extension) == 0) { $msg .= $text['message-required']." ".$text['label-extension']."
\n"; } - //if (strlen($ping) == 0) { $msg .= $text['message-required']." ".$text['label-ping']."
\n"; } if (strlen($channels) == 0) { //$msg .= $text['message-required']." ".$text['label-channels']."
\n"; $channels = 0; } - //if (strlen($caller_id_in_from) == 0) { $msg .= $text['message-required']." ".$text['label-caller_id_in_from']."
\n"; } - //if (strlen($supress_cng) == 0) { $msg .= $text['message-required']." ".$text['label-supress_cng']."
\n"; } - //if (strlen($sip_cid_type) == 0) { $msg .= $text['message-required']." ".$text['label-sip_cid_type']."
\n"; } - //if (strlen($codec_prefs) == 0) { $msg .= $text['message-required']." ".$text['label-codec_prefs']."
\n"; } - //if (strlen($extension_in_contact) == 0) { $msg .= $text['message-required']." ".$text['label-extension_in_contact']."
\n"; } if (strlen($context) == 0) { $msg .= $text['message-required']." ".$text['label-context']."
\n"; } if (strlen($profile) == 0) { $msg .= $text['message-required']." ".$text['label-profile']."
\n"; } if (strlen($enabled) == 0) { $msg .= $text['message-required']." ".$text['label-enabled']."
\n"; } - //if (strlen($description) == 0) { $msg .= $text['message-required']." ".$text['label-description']."
\n"; } if (strlen($msg) > 0 && strlen($_POST["persistformvar"]) == 0) { require_once "resources/header.php"; require_once "resources/persist_form_var.php"; @@ -399,6 +382,7 @@ echo "\n"; echo "\n"; echo " \n"; + echo " \n"; //help defeat browser auto-fill echo "
\n"; echo $text['description-username']."\n"; echo "\n"; @@ -409,7 +393,8 @@ echo " ".$text['label-password']."\n"; echo "\n"; echo "\n"; - echo " \n"; + echo " \n"; //help defeat browser auto-fill + echo " \n"; echo "
\n"; echo " ".$text['description-password']."\n"; echo "\n"; diff --git a/core/users/user_edit.php b/core/users/user_edit.php index 5d430f049c..cd98acf30b 100644 --- a/core/users/user_edit.php +++ b/core/users/user_edit.php @@ -645,7 +645,7 @@ echo " "; if (permission_exists("user_edit")) { echo " \n"; - echo " \n"; + echo " \n"; //help defeat browser auto-fill } else { echo " ".escape($username)."\n"; @@ -657,7 +657,7 @@ echo " "; echo " ".$text['label-password'].""; echo " "; - echo " "; + echo " "; //help defeat browser auto-fill echo " "; echo "

\n"; if ((is_numeric($required['length']) && $required['length'] != 0) || $required['number'] || $required['lowercase'] || $required['uppercase'] || $required['special']) {