Ticket #30 (closed enhancement: fixed)

Opened 4 years ago

Last modified 3 years ago

0016692: [VPX beheer] Passwords worden in 'clear text' verstuurd

Reported by: admin Owned by:
Priority: major Milestone: MediaMosa 2.2
Component: CQL Version:
Keywords: Cc:
MoSCoW: Should Have Estimated time after impact analysis:
Related to project: none Tested: yes
Accepted: yes Estimated Hours:

Description


0016692: [VPX beheer] Passwords worden in 'clear text' verstuurd
 http://mantis.kennisnet.nl/view.php?id=16692

Bij het aanmaken van een account op de beheeromgeving van VPcore worden drie elementen in 1 clear text email verstuurd:
* waar je moet zijn
* username
* password

In ieder geval die laatste hoort onder geen enkele voorwaarde in zo'n mail thuis. In zo'n geval liever werken met een 'hash' die de gebruiker een password in laat voeren op een webpagina. Die webpagina dan natuurlijk versleuteld met https en niet http.

Change History

Changed 3 years ago by Frans

  • moscow set to Should Have
  • component set to CQL
  • related_to set to none
  • milestone changed from MediaMosa X.X to MediaMosa 2.2

Changed 3 years ago by robert

MediaMosa 2.x does not send the password anymore. It does send your user name, which is fine. When you create a new account, it will send you a email with a link that will allow you to setup your account. MediaMosa 2.x will never send you a password in email, it will always send a reset link instead.

If this is ok, then this ticket can be closed.

Changed 3 years ago by Frans

  • status changed from new to closed
  • tested set to yes
  • accepted changed from no to yes
  • resolution set to fixed

That is ok. There is still an issue with logging on to VP-Core Beheer using http in stead of https, but that is an VP-Core related issue.

Will close this one.

Changed 3 years ago by MC-arjen

with a (redundant) addition: the login of the ega is done by DBUS protocol, which also does not send passwords over the line.

Note: See TracTickets for help on using tickets.