[wp-trac] [WordPress Trac] #10589: Changeset 11804 breaks password reminder

WordPress Trac wp-trac at lists.automattic.com
Tue Aug 11 21:09:30 UTC 2009


#10589: Changeset 11804 breaks password reminder
-------------------------------+--------------------------------------------
 Reporter:  Denis-de-Bernardy  |       Owner:  westi                      
     Type:  defect (bug)       |      Status:  accepted                   
 Priority:  normal             |   Milestone:  2.8.4                      
Component:  Security           |     Version:  2.8.3                      
 Severity:  normal             |    Keywords:  has-patch reporter-feedback
-------------------------------+--------------------------------------------
Changes (by westi):

  * keywords:  has-patch => has-patch reporter-feedback
  * owner:  ryan => westi
  * status:  new => accepted
  * severity:  blocker => normal
  * priority:  high => normal


Comment:

 Why do we need to check the email.

 This code is processing the link that the user clicks on or copies from
 the email they are sent by the password reset request form.

 The data is never user entered and the email contains the username even
 when they specify an email address.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/10589#comment:2>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list