CF8 - Debug: Sensitive information is disclosed

Prevent sensitive information disclosure in ChronoForms debug mode.

Overview

Enabling debug mode can expose sensitive data to visitors and search engines.
Use the new debug status label in the forms list and configure the debug IP restriction setting to limit access.

Answered
rb rbock 16 Nov, 2024
1 Likes

If debug is enabled, sensitive information will be displayed to visitors and search engines!

There is also no way to quickly see if debug is enabled, e.g. in the form list.

A suggestion to enable debugging for only one or more IP addresses has so far been ignored.

I'm currently using a combination of Javascript and PHP to hide the debug field, at least for visitors.

However, that won't do much to deter search engines. And the sensitive information is still in the source code!

Max_admin Max_admin 16 Nov, 2024
Answer
1 Likes

I have added a new debug status label in the forms list along with a debug ip restriction setting

Max, ChronoForms developer
ChronoMyAdmin: Database administration within Joomla, no phpMyAdmin needed.
ChronoMails simplifies Joomla email: newsletters, logging, and custom templates.
rb rbock 17 Nov, 2024

Thank you... I am relieved!

This topic is locked and no more replies can be posted.