Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-17510

The reset password functionality is not affected by password strength rules

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 15.10-rc-1
    • 11.10.5, 15.8
    • Administration, User
    • None
    • Integration
    • Unknown
    • N/A
    • N/A

    Description

      Steps to reproduce :

      • Start a fresh wiki, configure it without guest access
      • Create a new user, let's call it "Bob"
      • Update the section "Users & Rights > Registration" of the administration, so that passwords require at least 12 characters
      • Bob lost his password, use the "Reset password" functionality to get an email with a reset password link
      • Clicking on the link, you can update Bob's password, but here you can put a weak password, something like "Yolololo", which is not 12 chars long.

      Attachments

        Issue Links

          Activity

            People

              surli Simon Urli
              caubin Clément Aubin
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: