Last modified: 2013-10-25 18:52:38 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T58002, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 56002 - Users getting generic message when resetting password to compromised hash, instead of recycled message
Users getting generic message when resetting password to compromised hash, in...
Status: RESOLVED FIXED
Product: Wikimedia
Classification: Unclassified
General/Unknown (Other open bugs)
wmf-deployment
All All
: Normal normal (vote)
: ---
Assigned To: Chris Steipp
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-22 16:44 UTC by Chris Steipp
Modified: 2013-10-25 18:52 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Chris Steipp 2013-10-22 16:44:40 UTC
Bug in the hook causes users to get a generic message about an extension aborting their password reset, instead of telling them that they were prevented from the change because they were resetting their password to one that matched the hashes that were potentially compromised.
Comment 1 Gerrit Notification Bot 2013-10-22 16:45:06 UTC
Change 91199 had a related patch set uploaded by CSteipp:
Fix error message for recycled passwords

https://gerrit.wikimedia.org/r/91199
Comment 2 Gerrit Notification Bot 2013-10-22 21:58:29 UTC
Change 91199 merged by jenkins-bot:
Fix error message for recycled passwords

https://gerrit.wikimedia.org/r/91199
Comment 3 Andre Klapper 2013-10-25 11:50:22 UTC
Patch merged - Is more work needed, or can this be closed as RESOLVED FIXED?

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links