Skip to content

Do not expose admin username in frontend #2256

@developerfromjokela

Description

@developerfromjokela

Hello!
motionEye seems to expose admin username in its HTML as javascript variable.
I think this is a potential security risk for brute-force and/or dictionary attacks towards the login system.

What was/is purpose of keeping that variable in HTML?

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions