Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-24837

The username field of the reset password form has no autocomplete attribute

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Major
    • None
    • 18.7.0
    • Authentication
    • Unknown

    Description

      The username field of the "Forgot your password" form does not carry an autocomplete attribute, so browsers and password managers cannot identify its purpose and do not offer the stored user name.

      This fails WCAG 2.1 success criterion 1.3.5 "Identify Input Purpose" (level AA, EN 301 549 9.1.3.5), which requires that a field collecting information about the user exposes its purpose programmatically.

      Steps to reproduce

      • Log out.
      • Go to /xwiki/bin/view/XWiki/ResetPassword.
      • Inspect the user name input.

      Actual behaviour

      The input is rendered as <input type="text" id="u" name="u" class="form-control" size="60" /> with no autocomplete attribute.

      Expected behaviour

      The input carries autocomplete="username", like the login and registration forms already do since XWIKI-18811 and XWIKI-18837.

      Location

      xwiki-platform-core/xwiki-platform-web/xwiki-platform-web-templates/src/main/resources/templates/resetpasswordinline.vm, line 72.

      Note that step 2 of the same flow is already correct: the new-password fields go through definePasswordFields in register_macros.vm and carry autocomplete="new-password".

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              Lucas C Charpentier Lucas
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated: