Skip to content

Make the Dataverse token field plain text - #282

Open
jodeleeuw wants to merge 1 commit into
testfrom
fix/dataverse-token-text-field
Open

jodeleeuw wants to merge 1 commit into
testfrom
fix/dataverse-token-text-field

Conversation

@jodeleeuw

Copy link
Copy Markdown
Member

Refs #278.

Why

The reporter of #278 could not connect Harvard Dataverse from Chrome, even with a freshly generated token. The same token worked in Firefox.

The token field was type="password" with autocomplete="off". Chrome ignores autocomplete="off" on password fields and fills in the saved DataPipe login password. The field is masked, so a researcher who pastes without clearing it sends their password followed by the token. Dataverse rejects that, and the dashboard shows "did not accept the token." This is the most likely cause; the reporter hasn't confirmed it.

Masking protects little here. The installation shows the token in plain text, and we never display it after saving. It did hide the mistake that broke the connect. A password field could also lead Chrome to offer to save the token as the site password, replacing the researcher's saved login.

What

  • Change the token input to a text field with autoComplete="off", autoCapitalize="off", autoCorrect="off" and spellCheck={false}.
  • Add data-1p-ignore and data-lpignore="true" so 1Password and LastPass don't fill the field.
  • Show the token in a monospace font so it's easier to check.
  • Add a test that checks the field type and the autofill-blocking attributes.

Not checked in a real Chrome yet; the new jsdom test only checks the field's attributes. Worth trying on the test site with a saved login before merging.

Related: #280, which logs what the Dataverse server returns when it rejects a token.

🤖 Generated with Claude Code

The token input was type="password" with autocomplete="off", which
Chrome ignores on password fields: it filled in the saved DataPipe
login, the pasted token landed after it behind the mask, and Dataverse
rejected the combined string (#278, which then worked in Firefox).

Masking bought little -- the installation shows the token in the clear
-- and hid exactly the mistake that broke the connect. Use a text field
with autofill, autocorrect, and password-manager filling turned off.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant