[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059235#comment-16059235 ] Jacques Le Roux commented on OFBIZ-4361: +1 for sending an email with a link to verify -1 to check

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread JIRA
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059143#comment-16059143 ] Tobias Laufkötter commented on OFBIZ-4361: -- bq. Yes, we should check if a user login with this

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Michael Brohl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059128#comment-16059128 ] Michael Brohl commented on OFBIZ-4361: -- ??Verify email before sending link to provided email address,

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059113#comment-16059113 ] Deepak Dixit commented on OFBIZ-4361: - +1 make sense, I think we need to keep following point in

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Michael Brohl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059096#comment-16059096 ] Michael Brohl commented on OFBIZ-4361: -- We will provide a patch for review and further discussion. >

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Michael Brohl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059053#comment-16059053 ] Michael Brohl commented on OFBIZ-4361: -- The downsides of a security question are: * the user must

[jira] [Commented] (OFBIZ-4361) Any ecommerce user has the ability to reset anothers password (including admin) via "Forget Your Password"

2017-06-22 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-4361?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16059009#comment-16059009 ] Deepak Dixit commented on OFBIZ-4361: - I think we can use this by OFBIZ-436, we can ask user for

<    1   2