[SAC] Fwd: OSGeo Wiki email address confirmation

Sandro Santilli strk at kbt.io
Wed Mar 15 02:37:59 PDT 2017


On Wed, Mar 15, 2017 at 07:06:21AM +0000, Jachym Cepicky wrote:
> Hi Administrators, can you please have alook at this?

I've approved Julia Wagemann wiki application this morning, after
the mail from Margherita Di Leo which you can read in a separate
thread.

Sometimes links are pre-visited by some mail user agents
(or other bots: antivirus?) so they become invalid as used
already. The consequence is that the account creation is
confirmed.

NOTE that this is a bad security issue for users, so if anyone
is having such issue it his highly recommended to change MUA !

In any case, feel free to file a trac ticket to request that
confirmation takes more than a single visit but rather an
actual post of a form... (both for LDAP and Wiki)

--strk;

> 
> thanks
> 
> j
> 
> ---------- Forwarded message ---------
> From: Julia Wagemann <wagemann.julia at gmx.de>
> Date: Wed, Mar 15, 2017, 07:27
> Subject: Re: OSGeo Wiki email address confirmation
> To: OSGeo Wiki <info at osgeo.org>
> 
> 
> Dear Sir or Madam,
> I requested an account for OSGeo Wiki and received email below.
> Unfortunately, the link below does not work. Can you please help me?
> Thanks in advance,
> Julia Wagemann
> 
> 
> Am 12/03/2017 um 14:48 schrieb OSGeo Wiki:
> > Someone, probably you from IP address 95.148.198.74, has requested an
> account "Jwagemann" with this email address on OSGeo Wiki.
> >
> > To confirm that this account really does belong to you on OSGeo Wiki,
> open this link in your browser:
> >
> > //
> wiki.osgeo.org/index.php?title=Special:RequestAccount&action=confirmemail&wpEmailToken=e15d507297dd2f86e282823029faad9f
> >
> > If the account is created, only you will be emailed the password.
> > If this is *not* you, do not follow the link.
> > This confirmation code will expire at 14:48, 11 April 2017.
> >


More information about the Sac mailing list