[GeoNode-users] Script is registering users

Muhammad mnabiahmad at gmail.com
Fri Aug 25 01:09:25 PDT 2017


Thanks for the email.

Yes the script is from outside.

I think some one is using the /account/signup  form and extracts value 
of csfmidlewaretoken fills in rest of the values to server for 
registration.

Is /account/signup form the only way to register a user?

On 08/25/2017 11:00 AM, Alessio Fabiani wrote:
> A script from where? Outside?
>
> Regards,
>
> Alessio Fabiani
>
> ==
> GeoServer Professional Services from the experts! Visit 
> http://goo.gl/it488V for more information.
> ==
>
> Ing. Alessio Fabiani
>
> @alfa7691
> Founder/Technical Lead
>
>
> GeoSolutions S.A.S.
> Via di Montramito 3/A
> 55054  Massarosa (LU)
> Italy
> phone: +39 0584 962313
> fax:     +39 0584 1660272
> mob:   +39 331 6233686
>
> http://www.geo-solutions.it
> http://twitter.com/geosolutions_it
>
> -------------------------------------------------------
>
> AVVERTENZE AI SENSI DEL D.Lgs. 196/2003
>
> Le informazioni contenute in questo messaggio di posta elettronica e/o 
> nel/i file/s allegato/i sono da considerarsi strettamente riservate. 
> Il loro utilizzo è consentito esclusivamente al destinatario del 
> messaggio, per le finalità indicate nel messaggio stesso. Qualora 
> riceviate questo messaggio senza esserne il destinatario, Vi preghiamo 
> cortesemente di darcene notizia via e-mail e di procedere alla 
> distruzione del messaggio stesso, cancellandolo dal Vostro sistema. 
> Conservare il messaggio stesso, divulgarlo anche in parte, 
> distribuirlo ad altri soggetti, copiarlo, od utilizzarlo per finalità 
> diverse, costituisce comportamento contrario ai principi dettati dal 
> D.Lgs. 196/2003.
>
> The information in this message and/or attachments, is intended solely 
> for the attention and use of the named addressee(s) and may be 
> confidential or proprietary in nature or covered by the provisions of 
> privacy act (Legislative Decree June, 30 2003, no.196 - Italy's New 
> Data Protection Code).Any use not in accord with its purpose, any 
> disclosure, reproduction, copying, distribution, or either 
> dissemination, either whole or partial, is strictly forbidden except 
> previous formal approval of the named addressee(s). If you are not the 
> intended recipient, please contact immediately the sender by 
> telephone, fax or e-mail and delete the information in this message 
> that has been received in error. The sender does not give any warranty 
> or accept liability as the content, accuracy or completeness of sent 
> messages and accepts no responsibility  for changes made after they 
> were sent or for other risks which arise as a result of e-mail 
> transmission, viruses, etc.
>
>
> On Wed, Aug 23, 2017 at 3:16 PM, Muhammad <mnabiahmad at gmail.com 
> <mailto:mnabiahmad at gmail.com>> wrote:
>
>     Hi Every one
>
>     I have noticed that a script is registering users in our geonode
>     instance. In our geonode settings,
>     ACCOUNT_EMAIL_CONFIRMATION_EMAIL = True and
>     ACCOUNT_EMAIL_CONFIRMATION_REQUIRED = True, thus,  when the script
>     registers a user, information goes into people_profile table (and
>     some other tables) and I get notification of failed email
>     delivery. Since the emails are fictitious and
>     "account_email_confirmation_email" is true, the "is_active" field
>     in people_profile remains false.
>
>     Is there a way to stop such a script.
>
>     thanks
>
>     -- 
>     best regards
>
>     Muhammad Nabi Ahmad
>
>     _______________________________________________
>     geonode-users mailing list
>     geonode-users at lists.osgeo.org <mailto:geonode-users at lists.osgeo.org>
>     https://lists.osgeo.org/mailman/listinfo/geonode-users
>     <https://lists.osgeo.org/mailman/listinfo/geonode-users>
>
>


-- 
best regards

Muhammad Nabi Ahmad
Twitter : mnabiahmad
Blog    : https://scriptndebug.wordpress.com/

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.osgeo.org/pipermail/geonode-users/attachments/20170825/94d27bfc/attachment-0001.html>


More information about the geonode-users mailing list