From 2f41a34ac44ccfa8542a123c98618856c0bb95c4 Mon Sep 17 00:00:00 2001 From: Josh de Leeuw Date: Wed, 30 Sep 2026 09:21:47 -0400 Subject: [PATCH] Make the Dataverse token field plain text The token input was type="password" with autocomplete="off", which Chrome ignores on password fields: it filled in the saved DataPipe login, the pasted token landed after it behind the mask, and Dataverse rejected the combined string (#278, which then worked in Firefox). Masking bought little -- the installation shows the token in the clear -- and hid exactly the mistake that broke the connect. Use a text field with autofill, autocorrect, and password-manager filling turned off. Co-Authored-By: Claude Opus 5.5 --- __tests__/provider-connections.test.jsx | 12 ++++++++++++ components/account/ProviderConnections.js | 15 ++++++++++++++- 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/__tests__/provider-connections.test.jsx b/__tests__/provider-connections.test.jsx index 6c0e208..a0c8a12 100644 --- a/__tests__/provider-connections.test.jsx +++ b/__tests__/provider-connections.test.jsx @@ -124,6 +124,18 @@ describe("ProviderConnections", () => { expect(window.location.assign).not.toHaveBeenCalled(); }); + it("static-token provider: the token field is plain text so browsers do not autofill a saved password", () => { + renderComponent(); + + fireEvent.click(screen.getByRole("button", { name: /^Connect Dataverse$/i })); + + const tokenInput = screen.getByLabelText(/API token/i); + expect(tokenInput).toHaveAttribute("type", "text"); + expect(tokenInput).toHaveAttribute("autocomplete", "off"); + expect(tokenInput).toHaveAttribute("data-1p-ignore"); + expect(tokenInput).toHaveAttribute("data-lpignore", "true"); + }); + it("static-token provider: Save posts token + serverUrl to connectstatictokenprovider", async () => { global.fetch.mockResolvedValue({ ok: true, diff --git a/components/account/ProviderConnections.js b/components/account/ProviderConnections.js index 210af96..be5c010 100644 --- a/components/account/ProviderConnections.js +++ b/components/account/ProviderConnections.js @@ -409,10 +409,23 @@ export default function ProviderConnections({ data }) { )} {provider.tokenLabel} + {/* Plain text, not type="password": Chrome ignores + autocomplete="off" on password fields and fills in the + saved DataPipe login, so a paste lands after it (#278). + Masking buys little -- the token is shown in the clear on + the installation's own page -- and seeing it lets the + researcher check what they pasted. The data-* attributes + keep 1Password and LastPass from filling it too. */} setApiToken(e.target.value)} /> {provider.tokenHelp && (