Menu

#11 Currently logged admin can modify user's password

open-fixed
nobody
None
6
2006-11-04
2006-09-07
No

An admin can modify a user password.
It shouldn't.
Worse, when an admin modifies a user without specifying
a password (for example when he modifies his rights),
it overrides the user's password with the admin's one.
See bug #1554349.

Discussion

  • Hervé Labas

    Hervé Labas - 2006-09-08

    Logged In: YES
    user_id=1378263

    Wow, this is huge (the replace part).
    I'll go into it.
    The possibility an admin has to change a user's password was
    initially wanted by the association I worked for. That's why.
    Thanks

     
  • Hervé Labas

    Hervé Labas - 2006-09-13
    • priority: 5 --> 6
     
  • Olivier Ramat

    Olivier Ramat - 2006-11-04
    • status: open --> open-fixed
     

Log in to post a comment.

MongoDB Logo MongoDB