---
** [tickets:#8125] Require password when confirming new email address**
**Status:** open
**Milestone:** unreleased
**Labels:** security
**Created:** Thu Sep 08, 2016 02:18 PM UTC by Dave Brondsema
**Last Updated:** Thu Sep 08, 2016 02:18 PM UTC
**Owner:** Dave Brondsema
We should require a valid login session when opening an email verification
link. This avoids the security risk of typos on new email addresses that could
potentially let someone else take over your account.
---
Sent from forge-allura.apache.org because dev@allura.apache.org is subscribed
to https://forge-allura.apache.org/p/allura/tickets/
To unsubscribe from further messages, a project admin can change settings at
https://forge-allura.apache.org/p/allura/admin/tickets/options. Or, if this is
a mailing list, you can unsubscribe from the mailing list.