Disabled User can Access Site by Resetting Password

RESOLVED FIXED

Status

--
major
RESOLVED FIXED
9 years ago
8 years ago

People

(Reporter: ryansnyder, Unassigned)

Tracking

Details

Steps to reproduce in MCC and Jetpack Gallery:

1. As an admin, remove the user's login access in the admin panel.
2. Visit /forgot
3. Insert the email address for that page.
4. A verification email is sent to that user. (It should not be sent)
5. Click the verification link.
6. The user has successfully logged in.
Fixed and Committed.

==

Sending        modules/auth/models/auth_user.php
Transmitting file data .
Committed revision r60129.
Status: NEW → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → FIXED

Updated

8 years ago
Component: jetpackgallery.mozillalabs.com → jetpackgallery.mozillalabs.com
Product: Websites → Websites Graveyard
You need to log in before you can comment on or make changes to this bug.