Menu

#296 More fields in /as accountinfo

1.4.x
open
nobody
NickServ (43)
5
2009-12-25
2009-12-25
Lucario
No

The following two fields should be added to AuthServ accountinfo, if possible.

e.g

-AuthServ- Email last set: 12/12/09 01:10 GMT

(Oset date/time should be included too in addition to normal changes initiated by the account owner)

Why it's useful:

"Email last set" would help users determine whether somebody has maliciously changed their email for example. If, say, a user let his friend use his computer/IRC client and the friend changes his AuthServ email when he's not looking, the user will be "alerted" that his email has been changed without permission when he checks his own accountinfo. Also, this would deter potential rogue helpers from changing users' AuthServ email without their permission. Let's say if I join #support authed, with the current system, the person helping me can change my email to anything he wants technically even if I did not tell him to. The helper could lie that I asked him to change the email and I could insist I didn't and it would be hard to see who's telling the truth. Services logs will not be useful in this case as it will only show that Helper X had a ticket open for me. If I was helped in a PM, nobody else will know for sure what happened other than the helper and myself. If I last changed my email in 2005 and the "Email last set" is in 2009 for example, then I will know that something is wrong. Without this field in accountinfo, the user could only realize the problem when he needs to use resetpass or authcookie (which could be a few months after the email has been changed). In an ideal world, helpers shouldn't change users' emails without their permission but there's no safeguard against this when I was on staff in mid 2009 so I hope something can be done. Cheers :)

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.