diff --git a/lib/form/password.php b/lib/form/password.php index 1883897edab..c157a47fad6 100644 --- a/lib/form/password.php +++ b/lib/form/password.php @@ -15,6 +15,16 @@ class MoodleQuickForm_password extends HTML_QuickForm_password{ */ var $_helpbutton=''; function MoodleQuickForm_password($elementName=null, $elementLabel=null, $attributes=null) { + global $CFG; + if (empty($CFG->xmlstrictheaders)) { + // no standard mform in moodle should allow autocomplete of passwords + // this is valid attribute in html5, sorry, we have to ignore validation errors in legacy xhtml 1.0 + $attributes = (array)$attributes; + if (!isset($attributes['autocomplete'])) { + $attributes['autocomplete'] = 'off'; + } + } + parent::HTML_QuickForm_password($elementName, $elementLabel, $attributes); } /** diff --git a/lib/form/passwordunmask.php b/lib/form/passwordunmask.php index b70f0d51f39..1f0b8045142 100644 --- a/lib/form/passwordunmask.php +++ b/lib/form/passwordunmask.php @@ -15,6 +15,15 @@ require_once($CFG->libdir.'/form/password.php'); class MoodleQuickForm_passwordunmask extends MoodleQuickForm_password { function MoodleQuickForm_passwordunmask($elementName=null, $elementLabel=null, $attributes=null) { + global $CFG; + if (empty($CFG->xmlstrictheaders)) { + // no standard mform in moodle should allow autocomplete of passwords + // this is valid attribute in html5, sorry, we have to ignore validation errors in legacy xhtml 1.0 + $attributes = (array)$attributes; + if (!isset($attributes['autocomplete'])) { + $attributes['autocomplete'] = 'off'; + } + } parent::MoodleQuickForm_password($elementName, $elementLabel, $attributes); } diff --git a/lib/formslib.php b/lib/formslib.php index 929b000b79d..84af253bb5f 100644 --- a/lib/formslib.php +++ b/lib/formslib.php @@ -139,6 +139,16 @@ abstract class moodleform { * @return object moodleform */ function moodleform($action=null, $customdata=null, $method='post', $target='', $attributes=null, $editable=true) { + global $CFG; + if (empty($CFG->xmlstrictheaders)) { + // no standard mform in moodle should allow autocomplete with the exception of user signup + // this is valid attribute in html5, sorry, we have to ignore validation errors in legacy xhtml 1.0 + $attributes = (array)$attributes; + if (!isset($attributes['autocomplete'])) { + $attributes['autocomplete'] = 'off'; + } + } + if (empty($action)){ $action = strip_querystring(qualified_me()); } diff --git a/lib/javascript-static.js b/lib/javascript-static.js index a20699010f8..2cd826118ba 100644 --- a/lib/javascript-static.js +++ b/lib/javascript-static.js @@ -876,13 +876,14 @@ function unmaskPassword(id) { try { // first try IE way - it can not set name attribute later if (chb.checked) { - var newpw = document.createElement(''); + var newpw = document.createElement(''); } else { - var newpw = document.createElement(''); + var newpw = document.createElement(''); } newpw.attributes['class'].nodeValue = pw.attributes['class'].nodeValue; } catch (e) { var newpw = document.createElement('input'); + newpw.setAttribute('autocomplete', 'off'); newpw.setAttribute('name', pw.name); if (chb.checked) { newpw.setAttribute('type', 'text'); diff --git a/login/signup.php b/login/signup.php index f3b83be65d3..fb27841c8b3 100644 --- a/login/signup.php +++ b/login/signup.php @@ -43,7 +43,7 @@ $PAGE->https_required(); $PAGE->set_url('/login/signup.php'); $PAGE->set_context(get_context_instance(CONTEXT_SYSTEM)); -$mform_signup = new login_signup_form(); +$mform_signup = new login_signup_form(null, null, 'post', '', array('autocomplete'=>'on')); if ($mform_signup->is_cancelled()) { redirect(get_login_url());