[wp-trac] [WordPress Trac] #28798: htaccess and protected option

WordPress Trac noreply at wordpress.org
Fri Oct 15 13:11:15 UTC 2021


#28798: htaccess and protected option
-------------------------------+------------------------------
 Reporter:  YU.Design          |       Owner:  (none)
     Type:  enhancement        |      Status:  reopened
 Priority:  normal             |   Milestone:  Awaiting Review
Component:  Posts, Post Types  |     Version:  4.0
 Severity:  normal             |  Resolution:
 Keywords:                     |     Focuses:
-------------------------------+------------------------------

Comment (by briandd):

 I had opened a similar request #52390

 Today i found this one, i wanted to comment the suggestion above, as it's
 pretty old.

 For everybody trying to do this: do not do it. Reset/login functions can
 be overriden with POST, so if you allow action=postpass , you also allow
 everything else. Maybe it was possible in the past but now it is not.

 I really think both pages should be separated..

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/28798#comment:6>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list