/user/password and /user/reset/{uid}/{timestamp}/{hash} paths should be banned as cosign handles that
| Comment | File | Size | Author |
|---|---|---|---|
| #3 | cosign-routing-2780881-3-8x.patch | 2.39 KB | el1_1el |
| routing.patch | 939 bytes | el1_1el |
/user/password and /user/reset/{uid}/{timestamp}/{hash} paths should be banned as cosign handles that
| Comment | File | Size | Author |
|---|---|---|---|
| #3 | cosign-routing-2780881-3-8x.patch | 2.39 KB | el1_1el |
| routing.patch | 939 bytes | el1_1el |
Comments
Comment #2
mlhess commentedThere are use cases where cosign and normal Drupal logins are used for authentication. This patch would remove normal Drupal users from resetting their passwords.
Comment #3
el1_1el commentedok. how about this instead.
Comment #5
mlhess commented