hehe, please file jira issue
On 12/26/06, Wendy Smoak <[EMAIL PROTECTED]> wrote:
I'm having trouble with new user registration. (The
creation->verification->change password flow works, but so do some
things that shouldn't.)
1. Register for an account
2. Ignore the confirmation email
3. Attempt to log in with the new userid. Leave the password blank
4. You are prompted to 'Change Password'
5. Leave the 'existing password' blank, and enter a new password (twice).
6. You are logged in and on the Edit Details screen
1a. The newly created account is not "Locked" (even though the
registration confirmation page says it will be.)
1b. Even if you log in as admin and lock the account, steps 3-5 still work.
4a. If you navigate away from the change password page without
completing it, you appear to be logged in and can see everything from
project groups down to build results. (Possibly related to [1] where
a guest user with no roles can also see everything.)
[1]
http://www.nabble.com/Projects-are-visible-to-a-guest-user-with-no-roles-t2873616s177.html
--
Wendy
--
I could give you my word as a Spaniard.
No good. I've known too many Spaniards.
-- The Princess Bride