
I have just started exploring Drupal and noticed something in the account settings page.

Specifically, I noticed that you do not ask for the current password before letting the user change their current one. Isn't this a minor security weakness, e.g. you could step away from your keyboard for a moment, only to discover that your co-worker has played a prank on you by changing your password.

(OK, OK. It's a contrived example, but I hope you follow the idea.)

Thanks in advance...

-- f