diff options
author | Jani Honkonen <jani.honkonen@digia.com> | 2012-02-03 16:57:58 +0200 |
---|---|---|
committer | Qt by Nokia <qt-info@nokia.com> | 2012-08-22 02:59:33 +0200 |
commit | c09e9f71173a698670d6c728291ee24f53d50800 (patch) | |
tree | eece03b674f7783807205b4aa01a097914ce4a6e /src/gui | |
parent | 1de75716d6f0691cc57feb21768f250236eebfd4 (diff) |
Fix undo and redo in QLineEdit when in password mode
There are some security issues with undo/redo. User should not be
able to get the erased password back in any situation. Therefore
redo must be disabled completely and undo is limited only for erasing
previously entered text.
Backported from Qt5 SHA1: 121062d8848986dcfaf421388a5603b3b48a1e58
Task-number: QTBUG-14226
Change-Id: Ia712f95e8a2e45537a95d48b70686a1a8dd95da2
Reviewed-by: Stephen Kelly <stephen.kelly@kdab.com>
Diffstat (limited to 'src/gui')
-rw-r--r-- | src/gui/widgets/qlinecontrol.cpp | 22 | ||||
-rw-r--r-- | src/gui/widgets/qlinecontrol_p.h | 4 |
2 files changed, 24 insertions, 2 deletions
diff --git a/src/gui/widgets/qlinecontrol.cpp b/src/gui/widgets/qlinecontrol.cpp index 8c7822cf53..d626bde61a 100644 --- a/src/gui/widgets/qlinecontrol.cpp +++ b/src/gui/widgets/qlinecontrol.cpp @@ -1202,6 +1202,13 @@ void QLineControl::internalUndo(int until) return; cancelPasswordEchoTimer(); internalDeselect(); + + // Undo works only for clearing the line when in any of password the modes + if (m_echoMode != QLineEdit::Normal) { + clear(); + return; + } + while (m_undoState && m_undoState > until) { Command& cmd = m_history[--m_undoState]; switch (cmd.type) { @@ -1891,6 +1898,21 @@ void QLineControl::processKeyEvent(QKeyEvent* event) event->accept(); } +bool QLineControl::isUndoAvailable() const +{ + // For security reasons undo is not available in any password mode (NoEcho included) + // with the exception that the user can clear the password with undo. + return !m_readOnly && m_undoState + && (m_echoMode == QLineEdit::Normal || m_history[m_undoState - 1].type == QLineControl::Insert); +} + +bool QLineControl::isRedoAvailable() const +{ + // Same as with undo. Disabled for password modes. + return !m_readOnly + && m_echoMode == QLineEdit::Normal + && m_undoState < m_history.size(); +} QT_END_NAMESPACE diff --git a/src/gui/widgets/qlinecontrol_p.h b/src/gui/widgets/qlinecontrol_p.h index 20ecdfd147..b5ae92fbe3 100644 --- a/src/gui/widgets/qlinecontrol_p.h +++ b/src/gui/widgets/qlinecontrol_p.h @@ -113,8 +113,8 @@ public: return (c != -1 ? c : 0); } - bool isUndoAvailable() const { return !m_readOnly && m_undoState; } - bool isRedoAvailable() const { return !m_readOnly && m_undoState < (int)m_history.size(); } + bool isUndoAvailable() const; + bool isRedoAvailable() const; void clearUndo() { m_history.clear(); m_modifiedState = m_undoState = 0; } bool isModified() const { return m_modifiedState != m_undoState; } |