Anonymous Login

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0000057SKGB-internneues-kennwortpublic2017-09-12 21:31
Reporteraj 
Assigned To 
PrioritynormalSeverityfeatureReproducibilityN/A
StatusresolvedResolutionwon't fix 
Projectionmajor reworkETAnone 
PlatformWWWOSiCabOS Version3.0b
Product Version1.0.1Product Build 
Target Version2.0Fixed in Version2.0 
Summary0000057: Confirmation page on new password confirm
DescriptionIt'd be nice if people had the opportunity to review their action before their new password is set. A click onto the appropiate link in the email would then lead to a page with both a cancel button and a new password button. See the RISK digest mailing list's behaviour as an example (http://www.risks.org/).
Additional InformationSecurity Considerations:
Implementing would lessen the impact of storing the name/password combo in clear in pwtickets.
TagsNo tags attached.
Attached Files

-Relationships
+Relationships

-Notes

~0004933

aj (manager)

As of 2.0 the new Access Code semantics no longer require a confirmation, making this issue moot.
+Notes