When passwords are generated, there is no check to ensure the password is not already in use, assigned to a previous node.

Although the chances of duplicates are low, this could in theory lead to a user accidentally getting access to nodes they should not.

I have attached a patch to ensure unique passwords, please let me know if the patch has not been created correctly.

CommentFileSizeAuthor
ensure_unique_passwords.patch1.07 KBgrahamu

Comments

danielb’s picture

Bit of a delay on this issue because I will have to organise this for both D6 and D7.

danielb’s picture

Status: Active » Fixed

Patch added to 6 and 7, cheers.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.