diff --git a/__tests__/provider-connections.test.jsx b/__tests__/provider-connections.test.jsx index 6c0e208..a0c8a12 100644 --- a/__tests__/provider-connections.test.jsx +++ b/__tests__/provider-connections.test.jsx @@ -124,6 +124,18 @@ describe("ProviderConnections", () => { expect(window.location.assign).not.toHaveBeenCalled(); }); + it("static-token provider: the token field is plain text so browsers do not autofill a saved password", () => { + renderComponent(); + + fireEvent.click(screen.getByRole("button", { name: /^Connect Dataverse$/i })); + + const tokenInput = screen.getByLabelText(/API token/i); + expect(tokenInput).toHaveAttribute("type", "text"); + expect(tokenInput).toHaveAttribute("autocomplete", "off"); + expect(tokenInput).toHaveAttribute("data-1p-ignore"); + expect(tokenInput).toHaveAttribute("data-lpignore", "true"); + }); + it("static-token provider: Save posts token + serverUrl to connectstatictokenprovider", async () => { global.fetch.mockResolvedValue({ ok: true, diff --git a/components/account/ProviderConnections.js b/components/account/ProviderConnections.js index 210af96..be5c010 100644 --- a/components/account/ProviderConnections.js +++ b/components/account/ProviderConnections.js @@ -409,10 +409,23 @@ export default function ProviderConnections({ data }) { )} {provider.tokenLabel} + {/* Plain text, not type="password": Chrome ignores + autocomplete="off" on password fields and fills in the + saved DataPipe login, so a paste lands after it (#278). + Masking buys little -- the token is shown in the clear on + the installation's own page -- and seeing it lets the + researcher check what they pasted. The data-* attributes + keep 1Password and LastPass from filling it too. */} setApiToken(e.target.value)} /> {provider.tokenHelp && (