users can post or comment on trac-hacks.org in the name of any registered user
|Reported by:||falkb||Owned by:||Ryan J Ollos|
|Cc:||Ryan J Ollos, Steffen Hoffmann, lkraav||Trac Release:|
I noticed I can comment on tickets here on trac-hacks.org as falkb without being asked for my password.
I have no problem with anonymous users posting or commenting with fictive names or email addresses. I think this is even a useful feature for people who are don't forced to register when they want to report something.
But I think if one tries to post or comment with a registered account name or registered email address, such action has to be acknowledged by a password barrier. This way one may still post with fictive names (fine with me), but is not allowed to post in the name of a known user without confirmation.
I think this is important to prevent account abuse.
Change History (49)
comment:39 Changed 3 years ago by
|Component:||TracHacks → AccountManagerPlugin|
|Owner:||changed from Michael Renzmann to Steffen Hoffmann|