Modify

Opened 8 years ago

Closed 8 years ago

Last modified 7 years ago

#682 closed defect (fixed)

User should know old password in order to change password

Reported by: dan@… Owned by: mgood
Priority: normal Component: AccountManagerPlugin
Severity: normal Keywords:
Cc: Trac Release: 0.9

Description

This is a pretty standard security thing. In an office of people using Trac, it prevents someone from locking a coworker out of their Trac account while they're at lunch...

Attachments (1)

require_old_password.diff (1.4 KB) - added by otaku42 8 years ago.
Patch: require old password to set a new one

Download all attachments as: .zip

Change History (5)

Changed 8 years ago by otaku42

Patch: require old password to set a new one

comment:1 follow-up: Changed 8 years ago by otaku42

The attached patch adds the requested feature. It is for trunk and has been lightly tested.

comment:2 in reply to: ↑ 1 ; follow-up: Changed 8 years ago by ThurnerRupert

Replying to otaku42:

The attached patch adds the requested feature. It is for trunk and has been lightly tested.

the most typical use case of resetting the password is when you forgot your old one. how does this patch solve this use case?

comment:3 in reply to: ↑ 2 Changed 8 years ago by anonymous

Replying to ThurnerRupert:

Replying to otaku42:

The attached patch adds the requested feature. It is for trunk and has been lightly tested.

the most typical use case of resetting the password is when you forgot your old one. how does this patch solve this use case?

ThurnerRupert, this issue isn't meant to address the use-case you are identifying. (I am the original filer of the ticket.) It's only meant to address the requirement that you know the old password in order to change it.

comment:4 Changed 8 years ago by mgood

  • Resolution set to fixed
  • Status changed from new to closed

(In [1709]) require users to enter current password in order to change their password or delete their accounts (fixes #682)

Add Comment

Modify Ticket

Action
as closed .
as The resolution will be set. Next status will be 'closed'.
to The owner will be changed from mgood. Next status will be 'closed'.
The resolution will be deleted. Next status will be 'reopened'.
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.