Closed (fixed)
Project:
Drupal.org site moderators
Component:
User account
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
10 Mar 2021 at 19:12 UTC
Updated:
15 Jun 2021 at 10:44 UTC
Jump to comment: Most recent
Comments
Comment #2
gisleRun-of-the-mill site moderators (such as myself) do not have access to any site logs. However, I shall leave this request open in case somebody is able to provide a better answer.
The reset password link is clickable by anyone. That somebody is else is able to click on it is not having any other effect than you receiving an email with a one-time link. Delete it, and nothing will happen. It is of course annoying if this is done multiple times, but I don't know how to protect against this.
Comment #3
avpadernoFor that kind of queries, the Drupal.org contact form is preferable. It avoids showing in public information that's better to keep private.
Comment #4
MixologicWe're not able to provide any PII about usage in our log files, and an IP address falls under that category of PII. I was able to discover their activity, but it is extremely limited, i.e. there is almost no other activity from their IP other than requesting the password reset.
I'll send a private email with the only other info we can provide.
Comment #5
MixologicWe're basically in a legal conundrum where we are unsure what we're legally allowed to provide.
We *want* to be able to unmask harassers, because we take harassment seriously, but we do not want to get into some weird legal situation where the harasser can take us to court for providing "their" information under the GDPR.
Comment #6
avpaderno@Mixologic It's also probable the IP used to make that password reset request wouldn't be much helpful, as who made the request could be able to use different IPs for each request/attack.
Comment #7
avpadernoI am closing this issue, as Mixologic already answered it.