[jira] [Updated] (OFBIZ-11188) Forgot Password feature in ecommerce needs an access to partymngr

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Updated] (OFBIZ-11188) Forgot Password feature in ecommerce needs an access to partymngr

Nicolas Malin (Jira)

     [ https://issues.apache.org/jira/browse/OFBIZ-11188?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Michael Brohl updated OFBIZ-11188:
----------------------------------
    Affects Version/s:     (was: Release Branch 18.12)
                           (was: Release Branch 17.12)

> Forgot Password feature in ecommerce needs an access to partymngr
> -----------------------------------------------------------------
>
>                 Key: OFBIZ-11188
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-11188
>             Project: OFBiz
>          Issue Type: Improvement
>          Components: framework
>    Affects Versions: Release Branch 13.07, Release Branch 14.12, Release Branch 15.12, Release Branch 16.11, Trunk
>            Reporter: Jacques Le Roux
>            Priority: Major
>
> As Pierre Smits initially reported in OFBIZ-4361
> bq. another issue is that to change their passwords ecommerce clients need to get access to partymngr.  I think that's not secure enough and restriction of the possible actions (eg only allowed to reset password) would be a good idea...
> It should be noted that it was already like that before OFBIZ-4361



--
This message was sent by Atlassian Jira
(v8.3.4#803005)