When setting up SSO for Moodle, I found that Client Secret is being saved and displayed as plain text without any restriction. Could you please change the plugin to hide it after saving initial setup ? Otherwise any Moodle admin can get into Plugin page and copy Client secret and Application id and essentially have working credentials to login to Microsoft 365 tenant:
