/user/password and /user/reset/{uid}/{timestamp}/{hash} paths should be banned as cosign handles that

CommentFileSizeAuthor
#3 cosign-routing-2780881-3-8x.patch2.39 KBel1_1el
routing.patch939 bytesel1_1el
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

el1_1el created an issue. See original summary.

mlhess’s picture

Status: Needs review » Needs work

There are use cases where cosign and normal Drupal logins are used for authentication. This patch would remove normal Drupal users from resetting their passwords.

el1_1el’s picture

ok. how about this instead.

  • mlhess committed 394f58c on 8.x-1.x authored by el1_1el
    Issue #2780881 by el1_1el: Need to ban password resets
    
mlhess’s picture

Status: Needs work » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.