Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Welcome screen leaks (slightly) security relevant information #7643

Copy link
Copy link
@perler

Description

@perler
Issue body actions

Is there an existing issue for this?

  • I have searched the existing issues

OS/Web Information

  • Web Browser: all
  • Local OS: all
  • Remote OS: all
  • Remote Architecture: all
  • code-server --version: : v4.108.1

Steps to Reproduce

  1. connect to URL

Expected

login mask

Actual

login mask with message:

Please log in below. Check the config file at /home/username/.config/code-server/config.yaml for the password.

This reveals at least the username at the system (and the location of the password) and is bad practice IMO.

Logs

Screenshot/Video

No response

Does this bug reproduce in native VS Code?

No, this works as expected in native VS Code

Does this bug reproduce in VS Code web?

No, this works as expected in VS Code web

Does this bug reproduce in GitHub Codespaces?

No, this works as expected in GitHub Codespaces

Are you accessing code-server over a secure context?

  • I am using a secure context.

Notes

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingSomething isn't workingtriageThis issue needs to be triaged by a maintainerThis issue needs to be triaged by a maintainer

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.