MDL-52952 forms: Fix chrome autofilling passwords again

In MDL-45772 a hack was introduced to some forms to stop browsers from
putting the user's password into password fields in forms unrelated to
logging in.

Chrome now no longer fills the user's password in the first password
field in the page. There now needs to be a plain text input above it
for the username too.
This commit is contained in:
John Okely
2016-03-11 10:26:50 +08:00
parent e8952c5951
commit 67cdf4efae
2 changed files with 3 additions and 5 deletions
+2 -4
View File
@@ -189,10 +189,6 @@ abstract class moodleform {
$this->_form->hardFreeze();
}
// HACK to prevent browsers from automatically inserting the user's password into the wrong fields.
$element = $this->_form->addElement('hidden');
$element->setType('password');
$this->definition();
$this->_form->addElement('hidden', 'sesskey', null); // automatic sesskey protection
@@ -2703,6 +2699,8 @@ class MoodleQuickForm_Renderer extends HTML_QuickForm_Renderer_Tableless{
$this->_collapseButtons = '';
$formid = $form->getAttribute('id');
parent::startForm($form);
// HACK to prevent browsers from automatically inserting the user's password into the wrong fields.
$this->_hiddenHtml .= prevent_form_autofill_password();
if ($form->isFrozen()){
$this->_formTemplate = "\n<div class=\"mform frozen\">\n{content}\n</div>";
} else {
+1 -1
View File
@@ -3662,5 +3662,5 @@ function get_formatted_help_string($identifier, $component, $ajax = false, $a =
* @return string HTML to prevent password autofill
*/
function prevent_form_autofill_password() {
return '<div class="hide"><input type="password" /></div>';
return '<div class="hide"><input type="text" /><input type="password" /></div>';
}