Email password on clear text?

48 views
Skip to first unread message

sw2band

unread,
Feb 17, 2014, 8:53:32 AM2/17/14
to web...@googlegroups.com
Good day:

I am developing my first web application with web2py, so I follow the "Setting up mail" section of the reference manual:

http://web2py.com/books/default/chapter/29/08/emails-and-sms#Setting-up-email

I have a concern with the mail.settings.login, because this expose my password on clear text (if the application is successful, more developers will have access to the code).

Is possible to get this credentials from the auth_user table?. So this would be encrypted and "synchronized" with my LDAP directory.

Thank You.

Niphlod

unread,
Feb 18, 2014, 3:27:13 PM2/18/14
to web...@googlegroups.com
who sends the email is totally unrelated to who the user is .... in fact, it's a "service" account that serves the only purpose of being an approved sender on the mail relay (a good rule of thumb, it shouldn't be backed by an inbox).
If you disclose your app to others, feel free to put that in a variable and say explicitely in the docs what it's needed to be set to have the application working when deployed elsewhere.
Reply all
Reply to author
Forward
0 new messages