[ https://issues.apache.org/jira/browse/OFBIZ-11188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17283154#comment-17283154 ]
Michael Brohl commented on OFBIZ-11188: --------------------------------------- Removing release branches as this is an improvement. > Forgot Password feature in ecommerce needs an access to partymngr > ----------------------------------------------------------------- > > Key: OFBIZ-11188 > URL: https://issues.apache.org/jira/browse/OFBIZ-11188 > Project: OFBiz > Issue Type: Improvement > Components: framework > Affects Versions: Release Branch 13.07, Release Branch 14.12, Release > Branch 15.12, Release Branch 16.11, Trunk > Reporter: Jacques Le Roux > Priority: Major > > As Pierre Smits initially reported in OFBIZ-4361 > bq. another issue is that to change their passwords ecommerce clients need to > get access to partymngr. I think that's not secure enough and restriction of > the possible actions (eg only allowed to reset password) would be a good > idea... > It should be noted that it was already like that before OFBIZ-4361 -- This message was sent by Atlassian Jira (v8.3.4#803005)