') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Set Autocomplete Off on Login Form by geraj1010 · Pull Request #44780 · apache/airflow · GitHub
Skip to content

Set Autocomplete Off on Login Form - #44780

Closed
geraj1010 wants to merge 2 commits into
apache:v2-10-testfrom
geraj1010:airflow_44019
Closed

Set Autocomplete Off on Login Form#44780
geraj1010 wants to merge 2 commits into
apache:v2-10-testfrom
geraj1010:airflow_44019

Conversation

@geraj1010

@geraj1010geraj1010 commented Dec 9, 2024

Copy link
Copy Markdown
Contributor

Closes#44019

Updated main Javascript to apply autocomplete="off" to both username and password inputs on login page. This will help prevent the browser from providing hints for the username (and password), as requested in the Issue.

Based on Flask-AppBuilder source code, i.e. https://github.com/dpgaspar/Flask-AppBuilder/tree/master/flask_appbuilder/templates/appbuilder/general/security (see login_db.html and login_ldap.html), this should work for both AUTH_DB (default) and AUTH_LDAP authentication, since they both apparently use the same HTML elements in the form.

…f for username and password input elements on AUTH_DB login page
Comment threadairflow/www/static/js/main.js Outdated
@geraj1010
geraj1010 changed the base branch from main to v2-10-testDecember 9, 2024 18:14
@uranusjruranusjr added area:UI Related to UI/UX. For Frontend Developers. legacy ui Whether legacy UI change should be allowed in PR and removed area:dev-tools area:API Airflow's REST/HTTP API area:production-image Production image improvements and fixes labels Dec 9, 2024
@uranusjr
uranusjr removed the request for review from ephraimbuddyDecember 9, 2024 19:52

@pierrejeambrunpierrejeambrun left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice, tested locally, working as expected.

Should we target main and backport instead of specifically targeting v2-10-test. When changes are compatible I believe main then backport is better to limit drift between the two branches, I tend to directly target v2-10-test for changes that are completely different and incompatible with main anymore. @ephraimbuddy what do you think ?

@ephraimbuddy

Copy link
Copy Markdown
Contributor

Nice, tested locally, working as expected.

Should we target main and backport instead of specifically targeting v2-10-test. When changes are compatible I believe main then backport is better to limit drift between the two branches, I tend to directly target v2-10-test for changes that are completely different and incompatible with main anymore. @ephraimbuddy what do you think ?

I agree with you. Main then backport, for changes that are a bit compatible otherwise a different PR targeting the test branch would be better

Comment threadairflow/www/static/js/main.js
@geraj1010

Copy link
Copy Markdown
ContributorAuthor

Closing this PR, since we decided to push this one to main and backtrack to v2-10-test.

New PR: #44929

@geraj1010
geraj1010 deleted the airflow_44019 branch December 14, 2024 05:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:UIRelated to UI/UX. For Frontend Developers.legacy uiWhether legacy UI change should be allowed in PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Autocomplete Attribute Not Disabled for Password Fields in Login Forms

5 participants

@geraj1010@ephraimbuddy@ashb@pierrejeambrun@uranusjr