Problem/Motivation

1) Editing SMTP Transport - the password value is understandably not shown but if the form is saved the password is set as empty
2) In the database the password is held in plain text (though in a blob) - its visible in: /devel/config/edit/symfony_mailer.mailer_transport.smtp

Steps to reproduce

as above

Proposed resolution

1) Managing the pw is not straightforward but suggest:
- if pw set - show a set of say 7 '*'
- on save - check if pw is 7 '*' and if so don't update - otherwise do
- also make pw mandatory and dont allow just any number of '*'

2) Ideally 2-way encrypt eg with https://www.drupal.org/project/encrypt

Remaining tasks

User interface changes

API changes

Data model changes

Comments

Jons created an issue. See original summary.

adamps’s picture

Title: Better handle editing Transport with password field » Saving SMTP Transport deletes existing password
Category: Feature request » Bug report

Thanks for the issue. In fact two issues😃.

1) is a bug, bit irritating to users, fairly quick to fix, hopefully soon.
2) is a new feature, quite complex and needs some thought, might take some time. swiftmailer used the key module directly, and the credential providers were hard-coded (not plugins). We should make a solution that will extend to all the 3rd-party transports.

Please can you raise a separate issue for 2)?

jons’s picture

imclean’s picture

@Jons, I do something like this in one of the modules I maintain. Leaving the password field blank doesn't overwrite the existing one. There's a separate checkbox for deleting the stored password.

In submitForm():

// Only save the password if it is not empty.
if (!empty($values['password'])) {
  $config->set('password', $values['password']);
}

// Check option to delete the password.
if (!empty($values['delete_password'])) {
  $config->set('password', '');
}
adamps’s picture

Status: Active » Needs review
StatusFileSize
new1.77 KB

Similar to #5, a slightly different way.

adamps’s picture

  • AdamPS committed 8b985a5 on 1.x
    Issue #3306822 by AdamPS: Saving SMTP Transport deletes existing...
adamps’s picture

Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.