fedora-infra / fas

Fedora Account System
https://admin.fedoraproject.org/accounts
GNU General Public License v2.0
40 stars 50 forks source link

no email verification on bugzilla email #239

Closed ryanlerch closed 3 years ago

ryanlerch commented 7 years ago

In FAS3 we accept a bugzilla email without checking if that user has control of that email.

as such, it is possible for a user to set their bugzilla email to the email of another user. If then the actual owner of the bugzilla email / account tries to add the email to their account, when editing their profile, they get the following form validation error like:

Bugzilla email: <name>@<domain>.com exists already!
ryanlerch commented 7 years ago

This applies to the IRC nick too, another user can 'steal' someones IRC nick, causing them to to be able to set it in FAS

pandyamarut commented 6 years ago

May be once used nick , cant be used again. this might help. Look for it.

ryanlerch commented 3 years ago

Closing this issue as the FAS project is now archived, not actively developed, and unmaintained.

FAS was replaced in March 2021 by Fedora Accounts (https://accounts.fedoraproject.org).

If this issue is a Feature Request that you forsee might be beneficial to Fedora Accounts, please refile it against Noggin