#8125 Require password when confirming new email address

v1.6.0
closed
security (34)
General
nobody
2016-12-14
2016-09-08
No

We should require a valid login session when opening an email verification link. This avoids the security risk of typos on new email addresses that could potentially let someone else take over your account.

Discussion

  • Dave Brondsema

    Dave Brondsema - 2016-09-08
    • status: open --> review
     
  • Dave Brondsema

    Dave Brondsema - 2016-09-08

    Fixed on db/8125

     
  • Kenton Taylor - 2016-09-09

    Fix looks good, clear to merge.

     
  • Dave Brondsema

    Dave Brondsema - 2016-09-09
    • status: review --> closed
     
  • Dave Brondsema

    Dave Brondsema - 2016-12-14
    • Milestone: unreleased --> v1.6.0
     

Log in to post a comment.