[SAC] [OSGeo] #1804: password reset resets wrong password if a user has >1 account on an email address

OSGeo trac_osgeo at osgeo.org
Fri Oct 14 02:48:00 PDT 2016


#1804: password reset resets wrong password if a user has >1 account on an email
address
---------------------------+-------------------
 Reporter:  rduivenvoorde  |      Owner:  sac@…
     Type:  task           |     Status:  new
 Priority:  normal         |  Milestone:
Component:  Systems Admin  |   Keywords:
---------------------------+-------------------
 Somebody (well I'm not aware it was myself) created a (now removed) user
 'test' in ldap, and used my email address with it, which already is used
 in my personal user account...

 BUT trying to reset the 'test' user, my own account's password was
 actually rest as shown in the email:
 The temporary password for the OSGeo Userid "rduivenvoorde" is "****".

 So we cannot even rest the test-user password.

 I think it should not be possible to add a user with an already
 available/used email address?

 OR the reset form should work on account name and not with email address?

--
Ticket URL: <https://trac.osgeo.org/osgeo/ticket/1804>
OSGeo <http://www.osgeo.org/>
OSGeo committee and general foundation issue tracker.


More information about the Sac mailing list