https://bugzilla.wikimedia.org/show_bug.cgi?id=27751

           Summary: Should not show if username exists on failed login on
                    private wikis.
           Product: MediaWiki
           Version: 1.18-svn
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: enhancement
          Priority: Normal
         Component: User login
        AssignedTo: wikibugs-l@lists.wikimedia.org
        ReportedBy: bawolff...@gmail.com


Currently on failed log in, users are shown different messages if the username
does or does not exist. If anons don't have read rights to special:listusers,
the same message for auth failure should be used regardless of if the tried
username exists or not.

Otherwise a user could discover who has an account at the secret cabal wikis by
trying different account names in the log in form and observing the error
message.

This was discussed the other day on irc, and I thought i'd file a bug so it
isn't forgotten about.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to