Last modified: 2014-07-11 05:52:25 UTC
Before Gerrit change #94406 it was possible to confirm a email code without the need of login to (any) user account. This was changed and produced bug 60433. In my opinion the old behaviour should be restored. If not, the logged in user should be checked against the user which gets confirmed, because that can differ at the moment.
I'm okay with doing this either way.
Change 145511 had a related patch set uploaded by Rohan013: Login check in Special:Confirmemail was removed https://gerrit.wikimedia.org/r/145511