Reset password function provides usernames

XMLWordPrintable

    • Severity 3 - Minor
    • 2

      If you use the reset password function you can find out three groups of users:

      • user is local or in a read/write user directory
      • user is in a read only user directory
      • user does not exists

      This information should not be visible outside. Such information is helpful in a logfile, but the user should only the see a message like "If you are a registered user you should receive a password reset message.".

        1. local-user_ldap-write-user.PNG
          local-user_ldap-write-user.PNG
          8 kB
        2. no-user.PNG
          no-user.PNG
          10 kB
        3. ldap-read-user.PNG
          ldap-read-user.PNG
          11 kB

            Assignee:
            Hendrik (Inactive)
            Reporter:
            Deleted Account (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: