Currently the user form is altered to prevent the entering of passwords locally. Which is excellent and works.
But this prevention is not implemented on the password reset page.
Fix would be to add a form validation to check the entered name/email, using the same validation that is used on the form alters for the user edit pages.
| Comment | File | Size | Author |
|---|---|---|---|
| #5 | openid_connect-add_validation_to_password_reset_form-3071318-5.patch | 2.32 KB | thomasdik |
| #4 | openid_connect-add_validation_to_password_reset_form-3071318-4.patch | 2.48 KB | jefuri |
Comments
Comment #2
jefuri commentedComment #3
jefuri commentedComment #4
jefuri commentedComment #5
thomasdik commentedComment #6
jcnventuraLet's assume that after all this time, there's no reason to keep it assigned.
Comment #7
mcdruid commentedUnpublishing as this is similar to SA-CONTRIB-2021-006 and will be discussed in the private security issue tracker for now.
Comment #11
gisleComment #12
gisleComment #13
drummPublishing since this was fixed with https://www.drupal.org/sa-contrib-2021-014
Please report potential security issues confidentially in the future.