https://bugzilla.wikimedia.org/show_bug.cgi?id=29135

Chad H. <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |[email protected]

--- Comment #2 from Chad H. <[email protected]> 2011-05-25 13:00:24 UTC 
---
(In reply to comment #0)
> - evil users can trigger sending a new password to an arbitrary users
> 

Then the code is wrong for allowing a user to reset the password of another.

(In reply to comment #1)
> Status quo: 
> $wgGroupPermissions["*"]["isallowed-to-reset-other-user-password"] = true;
> 

That's the status quo? I was under the impression this feature was never
implemented (I attempted it, but was reverted).

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to