Jump to content

Confirm Password Reset


John

Recommended Posts

The 'Confirm Password Reset' page has two flaws in it. I am not sure if this is fixed in v4.0, if someone could confirm that as well, that would be great.

1. The page title is missing. It only displays the company name, and does not include $lang['ClientLogin.confirmreset.page_title'] in the title of the page. This is the only login type page that has this behavior. I checked 3 different Blesta installs, including the one at account.blesta.com, and they all had this issue.

2. The password reset link does not expire after one use. This could be an issue, because if someone has access to your email even for a minute, they can generate a link that will get them into your Blesta account forever.

I did not test either of these issues with the staff interface, only the client interface.

Link to comment
Share on other sites

  • 1 month later...

Thanks for the report.

 

On 10/15/2016 at 4:59 PM, John said:

The 'Confirm Password Reset' page has two flaws in it. I am not sure if this is fixed in v4.0, if someone could confirm that as well, that would be great.

1. The page title is missing. It only displays the company name, and does not include $lang['ClientLogin.confirmreset.page_title'] in the title of the page. This is the only login type page that has this behavior. I checked 3 different Blesta installs, including the one at account.blesta.com, and they all had this issue.

We'll take a look at the page title.

On 10/15/2016 at 4:59 PM, John said:

2. The password reset link does not expire after one use. This could be an issue, because if someone has access to your email even for a minute, they can generate a link that will get them into your Blesta account forever.

I did not test either of these issues with the staff interface, only the client interface.

The password reset link included in an email is only accessible for a short period of time. By default, it is available for 4 hours and can be changed in the config file for 'Blesta.reset_password_ttl'.

Link to comment
Share on other sites

5 hours ago, Tyson said:

The password reset link included in an email is only accessible for a short period of time. By default, it is available for 4 hours and can be changed in the config file for 'Blesta.reset_password_ttl'.

But normally if the link was visited and password was change it should be removed and has no effect , thought no ?

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
×
×
  • Create New...