[jira] [Commented] (OFBIZ-11188) Forgot Password feature in ecommerce needs an access to partymngr

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Commented] (OFBIZ-11188) Forgot Password feature in ecommerce needs an access to partymngr

Nicolas Malin (Jira)

    [ https://issues.apache.org/jira/browse/OFBIZ-11188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17283154#comment-17283154 ]

Michael Brohl commented on OFBIZ-11188:
---------------------------------------

Removing release branches as this is an improvement.

> Forgot Password feature in ecommerce needs an access to partymngr
> -----------------------------------------------------------------
>
>                 Key: OFBIZ-11188
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-11188
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: framework
>    Affects Versions: Release Branch 13.07, Release Branch 14.12, Release Branch 15.12, Release Branch 16.11, Trunk
>            Reporter: Jacques Le Roux
>            Priority: Major
>
> As Pierre Smits initially reported in OFBIZ-4361
> bq. another issue is that to change their passwords ecommerce clients need to get access to partymngr.  I think that's not secure enough and restriction of the possible actions (eg only allowed to reset password) would be a good idea...
> It should be noted that it was already like that before OFBIZ-4361



--
This message was sent by Atlassian Jira
(v8.3.4#803005)