This is a snapshot of Indico's old Trac site. Any information contained herein is most probably outdated. Access our new GitHub site here.

Opened 4 years ago

Closed 23 months ago

#914 closed defect (fixed)

When adding secondary email, trigger notification

Reported by: jbenito Owned by: arescope
Priority: blocker Milestone: v1.2
Component: Security Version:
Keywords: Cc:

Description

When adding a secondary email address, Indico should trigger an email to make sure that this email address belongs to that user.
This can be a security problem if we use email to grant access to some info (to check if we do)

Change History (9)

comment:1 Changed 4 years ago by jbenito

  • Priority changed from high to critical

Another examples:

  1. If we grant submission, chair, etc rights to somebody that is not on Indico, Indico will send the an email to the guy. If we create an account with that guy's email before he does, we get his credentials.
  2. Another one that it is not so critical is to access an abstract (just to view). All the authors have access by email. I need just to create an account with those emails and the access is granted.

comment:2 Changed 3 years ago by jbenito

  • Milestone changed from v0.98.1 to v0.99.0
  • Owner set to arescope
  • Status changed from new to assigned

comment:3 Changed 3 years ago by arescope

  • Milestone changed from v0.99.0 to v1.0

comment:4 Changed 3 years ago by jbenito

  • Milestone changed from v1.0 to v1.1
  • Priority changed from critical to blocker

comment:5 Changed 2 years ago by jbenito

  • Milestone changed from v1.1 to v1.2

comment:6 Changed 2 years ago by arescope

  • Status changed from assigned to in_work

comment:7 Changed 2 years ago by arescope

  • Status changed from in_work to awaiting_merge

comment:8 Changed 2 years ago by jbenito

  • Status changed from awaiting_merge to merging

comment:9 Changed 23 months ago by jbenito

  • Resolution set to fixed
  • Status changed from merging to closed
Note: See TracTickets for help on using tickets.