3 ms·
Any form meaning passwords too?
by Lu2025 1y ago
Any form meaning passwords too?
- perching_aix 1y agoLooked into it, the answer seems like it can be both a yes or a no, depending on the website and user actions. By default, when you implement a form that takes a password, you (the developer) are going to be using the "input" HTML element with the type "password". This element is exempt from spellchecking, so no issues there. However, many websites also implement a temporary password reveal feature. To achieve this, one would typically change the type of the "input" element to "text" when clicking the reveal button, thereby unintentionally allowing spellchecking. You (the developer) can explicitly mark an element to be ineligible for spellchecking by setting the "spellchecking" attribute to "false", remediating this quirk: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/Global_attributes/spellcheck https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/... You (the developer) can of course also just use a different approach for implementing a password reveal feature. As the MDN docs remark, this infoleak vector is known as "spelljacking".