mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #10282
[Bug 1045123] [NEW] don't send out password for admin created users
*** This bug is a security vulnerability ***
Public security bug reported:
When an admin creates a user with a set password. It should be assumed that this password is delivered to the user out of band, and shouldn't be sent in clear text.
If the password field is left blank, we should treat that the same as if we just finished a registration, the user gets a one time URL to click on which forces them to set a password.
** Affects: mahara
Importance: Medium
Status: Triaged
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/1045123
Title:
don't send out password for admin created users
Status in Mahara ePortfolio:
Triaged
Bug description:
When an admin creates a user with a set password. It should be assumed that this password is delivered to the user out of band, and shouldn't be sent in clear text.
If the password field is left blank, we should treat that the same as if we just finished a registration, the user gets a one time URL to click on which forces them to set a password.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1045123/+subscriptions
Follow ups
-
[Bug 1045123] Re: don't send out password for admin created users
From: Kristina Hoeppner, 2016-03-13
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2015-10-23
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2015-04-21
-
[Bug 1045123] Re: don't send out password for admin created users
From: Robert Lyon, 2015-04-17
-
[Bug 1045123] Re: don't send out password for admin created users
From: Kristina Hoeppner, 2014-11-11
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2014-11-11
-
[Bug 1045123] Re: don't send out password for admin created users
From: Kristina Hoeppner, 2014-09-07
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2014-04-15
-
[Bug 1045123] Re: don't send out password for admin created users
From: Son Nguyen, 2014-03-24
-
[Bug 1045123] Re: don't send out password for admin created users
From: Kristina Hoeppner, 2014-03-24
-
[Bug 1045123] Re: don't send out password for admin created users
From: Son Nguyen, 2014-03-23
-
[Bug 1045123] Re: don't send out password for admin created users
From: Son Nguyen, 2014-03-23
-
[Bug 1045123] Re: don't send out password for admin created users
From: Son Nguyen, 2013-12-13
-
[Bug 1045123] Re: don't send out password for admin created users
From: Kristina Hoeppner, 2013-12-06
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-12-05
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-12-04
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-12-04
-
[Bug 1045123] Re: don't send out password for admin created users
From: Son Nguyen, 2013-12-04
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-10-01
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-09-30
-
[Bug 1045123] Re: don't send out password for admin created users
From: Aaron Wells, 2013-04-19
-
[Bug 1045123] Re: don't send out password for admin created users
From: Hugh Davenport, 2012-09-02
-
[Bug 1045123] [NEW] don't send out password for admin created users
From: Hugh Davenport, 2012-09-02
References