savannah-hackers
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Savannah-hackers] [task #3425] Reassigned item: bugs in email address c


From: Sylvain Beucler
Subject: [Savannah-hackers] [task #3425] Reassigned item: bugs in email address change confirmation
Date: Sat, 21 Aug 2004 19:53:42 -0400
User-agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.6) Gecko/20040207 Firefox/0.8

This mail is an automated notification from the task tracker
 of the project: Savannah Administration.

/**************************************************************************/
[task #3425] Latest Modifications:

Changes by: 
                Sylvain Beucler <address@hidden>
'Date: 
                Sat 08/21/2004 at 23:49 (Europe/Paris)

            What     | Removed                   | Added
---------------------------------------------------------------------------
     Should Start On |                           | Sat 08/21/2004 at 00:00
Should be Finished on |                           | Sat 08/21/2004 at 00:00
          Resolution | None                      | Done
         Assigned to | None                      | beu
              Status | Open                      | Closed


------------------ Additional Follow-up Comments ----------------------------
Elfyn just fixed it.






/**************************************************************************/
[task #3425] Full Item Snapshot:

URL: <http://savannah.gnu.org/task/?func=detailitem&item_id=3425>
Project: Savannah Administration
Submitted by: Norbert Bollow
On: Sat 08/21/2004 at 23:43

Should Start On:  Sat 08/21/2004 at 00:00
Should be Finished on:  Sat 08/21/2004 at 00:00
Category:  None
Priority:  5 - Normal
Resolution:  Done
Privacy:  Public
Assigned to:  beu
Percent Complete:  0%
Status:  Closed
Effort:  0.00


Summary:  Reassigned item: bugs in email address change confirmation

Original Submission:  There are several problems in the system for confirming 
email address change.

The most serious issue is that the confirmation email which is intended to be 
sent to the new email address goes to the old email address instead, so that it 
does not achieve its intended purpose of ensuring that the new email address 
works.

The warning email which should go to the old email address goes to the new 
email address instead.  Also there is a typo in this email message... "if 
maybe" should read "is maybe".

The system also generates a bogus error message "Database updated [#1]; The 
system reported a failure when trying to send the confirmation mail. please 
retry and report that problem to administrators [#2];" (I received those 
confirmation emails alright.)




Follow-up Comments
------------------


-------------------------------------------------------
Date: Sat 08/21/2004 at 23:49       By: Sylvain Beucler <Beuc>
Elfyn just fixed it.

-------------------------------------------------------
Date: Sat 08/21/2004 at 23:43       By: Sylvain Beucler <Beuc>
This item has been reassigned from the project Savannah Administration bugs 
tracker to your tracker.

The original report is still available at bugs #6958

Following are the information included in the original report:

[field #0] <font class="preinput"><font class="help" title="Unique item 
identifier">Item ID: </font></font> 6958<br>[field #1] <font 
class="preinput"><font class="help" title="Unique project identifier">Group ID: 
</font></font> 5802<br>[field #2] <font class="preinput"><font class="help" 
title="Current Status">Status: </font></font> Open<br>[field #3] <font 
class="preinput"><font class="help" title="Impact of the item on the system 
(Critical, Major,...)">Severity: </font></font> 5 - Average<br>[field #4] <font 
class="preinput"><font class="help" title="Determines whether the item can be 
seen by members of the project only or anybody.">Privacy: </font></font> 
Public<br>[field #5] <font class="preinput"><font class="help" title="Generally 
high level modules or functionalities of the software (e.g. User interface, 
Configuration Manager, etc)">Category: </font></font> None<br>[field #6] <font 
class="preinput"><font class="help" title="User who originally submitted the
item">Submitted by: </font></font> nb<br>[field #7] <font 
class="preinput"><font class="help" title="Who is in charge of handling this 
item">Assigned to: </font></font> None<br>[field #8] <font 
class="preinput"><font class="help" title="Date and time of the initial 
submission">Submitted on: </font></font> Tue 12/23/2003 at 11:09<br>[field #9] 
<font class="preinput"><font class="help" title="One line description of the 
item">Summary: </font></font> bugs in email address change 
confirmation<br>[field #10] <font class="preinput"><font class="help" 
title="Full description of the item">Original Submission: </font></font> There 
are several problems in the system for confirming email address change.
<br />

<br />
The most serious issue is that the confirmation email which is intended to be 
sent to the new email address goes to the old email address instead, so that it 
does not achieve its intended purpose of ensuring that the new email address 
works.
<br />

<br />
The warning email which should go to the old email address goes to the new 
email address instead.  Also there is a typo in this email message... "if 
maybe" should read "is maybe".
<br />

<br />
The system also generates a bogus error message "Database updated [#1]; The 
system reported a failure when trying to send the confirmation mail. please 
retry and report that problem to administrators [#2];" (I received those 
confirmation emails alright.)
<br />

<br />

<br />
<br>[field #12] <font class="preinput"><font class="help" title="Characterizes 
the nature of the item (e.g. Crash Error, Documentation Typo, Installation 
Problem, etc">Item Group: </font></font> None<br>[field #13] <font 
class="preinput"><font class="help" title="Current resolution of the 
item">Resolution: </font></font> None<br>[field #14] <font 
class="preinput"><font class="help" title="Version of the System Component (aka 
Item Category) impacted by the item">Component Version: </font></font> 
None<br>[field #15] <font class="preinput"><font class="help" title="Name and 
version of the platform impacted by the item (GNU/Linux with kernel 2.4, 
FreeBSD 5.1,...)">Platform Version: </font></font> None<br>[field #16] <font 
class="preinput"><font class="help" title="How easy it is to reproduce the 
item">Reproducibility: </font></font> None<br>[field #17] <font 
class="preinput"><font class="help" title="Estimated size of the code to be 
developed or reworked to fix the
item">Size (loc): </font></font> None<br>[field #18] <font 
class="preinput"><font class="help" title="Release in which the item was 
actually fixed">Fixed Release: </font></font> None<br>[field #19] <font 
class="preinput"><font class="help" title="Release in which it is planned to 
have the item fixed">Planned Release: </font></font> None<br>[field #20] <font 
class="preinput"><font class="help" title="Number of hours of work needed to 
fix the item">Effort: </font></font> 0.00<br>[field #24] <font 
class="preinput"><font class="help" title="How quickly the item should be 
handled">Priority: </font></font> 5 - Normal<br>[field #27] <font 
class="preinput"><font class="help" title="">Percent Complete: </font></font> 
0%<br>[field #29] <font class="preinput"><font class="help" title="Release 
(global version number) impacted by the item">Release: </font></font> 
None<br>[field #54] <font class="preinput"><font class="help" 
title="Customizable Select Box (pull down menu with
predefined values)">Custom Select Box #1: </font></font> None<br>[field #55] 
<font class="preinput"><font class="help" title="Customizable Select Box (pull 
down menu with predefined values)">Custom Select Box #2: </font></font> 
None<br>[field #56] <font class="preinput"><font class="help" 
title="Customizable Select Box (pull down menu with predefined values)">Custom 
Select Box #3: </font></font> None<br>[field #57] <font class="preinput"><font 
class="help" title="Customizable Select Box (pull down menu with predefined 
values)">Custom Select Box #4: </font></font> None<br>[field #58] <font 
class="preinput"><font class="help" title="Customizable Select Box (pull down 
menu with predefined values)">Custom Select Box #5: </font></font> 
None<br>[field #59] <font class="preinput"><font class="help" 
title="Customizable Select Box (pull down menu with predefined values)">Custom 
Select Box #6: </font></font> None<br>[field #60] <font class="preinput"><font 
class="help"
title="Customizable Select Box (pull down menu with predefined values)">Custom 
Select Box #7: </font></font> None<br>[field #61] <font class="preinput"><font 
class="help" title="Customizable Select Box (pull down menu with predefined 
values)">Custom Select Box #8: </font></font> None<br>[field #62] <font 
class="preinput"><font class="help" title="Customizable Select Box (pull down 
menu with predefined values)">Custom Select Box #9: </font></font> 
None<br>[field #63] <font class="preinput"><font class="help" 
title="Customizable Select Box (pull down menu with predefined values)">Custom 
Select Box #10: </font></font> None<br>

-------------------------------------------------------
Date: Sun 02/29/2004 at 09:33       By: Sylvain Beucler <Beuc>
It seems e-mails go to the right addresses now:
- confirm to the new e-mail
- discard to the old e-mail
The only bug is that discarding after confirming does not put back the old 
e-mail, which means if you want an e-mail change, the system will send the 
'discard' e-mail to the new e-mail, that is the attacker's, and it will be 
difficult to put back the old adress if the attacker can discard the changes at 
any time. Moreover, the attacker still can have a password change e-mail to him 
meanwhile...

I moved the typo to support #6957

The bogus error message still appears and somebody has to check it.

-------------------------------------------------------
Date: Fri 01/23/2004 at 19:24       By: Paul D. Smith <psmith>
I see these problems with email sent to the wrong address too.

But not only that, the confirmation email is not correct; whenever I get the 
email and try to use the link I get an error saying the hash is incorrect, and 
my email address doesn't get changed.












For detailed info, follow this link:
<http://savannah.gnu.org/task/?func=detailitem&item_id=3425>

_______________________________________________
  Message sent via/by Savannah
  http://savannah.gnu.org/







reply via email to

[Prev in Thread] Current Thread [Next in Thread]