Skip to content

I can sign in by the account of non-register-user #269

Description

@keisukemizuno

I can sign in by the account of non-register-user, in this way.

  1. I register the account of 'test@example.com', in the /users/register
  2. I ignore the notification sent by activation email
  3. I input the account of 'test@example.com', in the /users/request-reset-password
  4. I click the link in email of reset-password
  5. I change the password

This case is almost no.
But, in this conditions, ( activation_date = NULL & active = 0 & token = '' )
there is no guarantee that it does not effect other functions, does it ?

The sorry please English is in poor.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions