Uploaded image for project: 'i2b2 Core Software'
  1. i2b2 Core Software
  2. CORE-283 Security enhancements
  3. CORE-300

Do not allow current password to be used as new password

    XMLWordPrintable

Details

    • Sub-Task
    • Status: Resolved
    • Major
    • Resolution: Done
    • None
    • 1.7.10
    • None
    • Rank:
      0|i003xb:
    • v1710.1

    Description

      Currently when a user changes their password they can enter the same password. In other words if their current password is demo, then they can enter demo as their "new" password. In 1.7.10 we introduce a new feature where administrators can enforce mandatory password changes. This bug creates a loophole around the requirement if users are able to reset their password to the same password.

      This check will only be relevant to the current password and the new password that they are entering.

      Attachments

        Activity

          People

            jmd86 Janice Donahoe
            jmd86 Janice Donahoe
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: