If you think a bug might affect users in the 57 release, please set the correct tracking and status flags for Release Management.

Disabled User can Access Site by Resetting Password

RESOLVED FIXED

Status

Websites
creative.mozilla.org
--
major
RESOLVED FIXED
8 years ago
8 years ago

People

(Reporter: ryansnyder, Unassigned)

Tracking

Details

Steps to reproduce in MCC and Jetpack Gallery:

1. As an admin, disable a user in the admin panel.
2. Visit /forgot
3. Insert the email address for that page.
4. A verification email is sent to that user. (It should not be sent)
5. Click the verification link.
6. The user has successfully logged in.
Fixed and committed.

==

Sending        modules/auth/models/auth_user.php
Transmitting file data .
Committed revision r60130.
Status: NEW → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.