[wp-trac] [WordPress Trac] #41136: Login forms lacking autocomplete attributes

WordPress Trac noreply at wordpress.org
Fri Mar 25 16:38:02 UTC 2022


#41136: Login forms lacking autocomplete attributes
------------------------------+--------------------------------------------
 Reporter:  johnjamesjacoby   |       Owner:  joedolson
     Type:  defect (bug)      |      Status:  accepted
 Priority:  normal            |   Milestone:  6.0
Component:  Login and         |     Version:
  Registration                |
 Severity:  normal            |  Resolution:
 Keywords:  needs-patch       |     Focuses:  accessibility, administration
------------------------------+--------------------------------------------
Changes (by joedolson):

 * owner:  (none) => joedolson
 * status:  new => accepted


Comment:

 From a technical standpoint, using any autocomplete on any field anywhere
 introduces the same security issue, so I'm not sure to what degree we
 should take responsibility for that. Any software can be used in both a
 private and a shared environment.

 There's a relevant conversation here:
 https://github.com/w3c/wcag/issues/2110

 One thing I think this will need is to provide a filter so that
 autocomplete can be disabled; sites with higher security needs might need
 an easy way to disable this feature.

 Overall, however, I think this is more of a benefit than a potential for
 harm. Would benefit from some additional voices on the security side,
 however.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/41136#comment:12>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list